论文标题
为什么,软件安全补丁管理中的延误以及何处:医疗保健领域的实证研究
Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare Sector
论文作者
论文摘要
导致毁灭性后果的许多安全攻击可以追溯到应用安全补丁的延迟。尽管及时的补丁应用程序至关重要,但在实践中应用安全补丁以及如何减轻延迟时,为什么以及如何发生延迟。基于从132个延迟修补任务中收集的纵向数据,以及对涉及医疗保健领域两个组织的八个团队的补丁会议的观察,并使用定量和定性数据分析方法,我们确定了与技术,人员和组织有关的一组理由,这是导致贴在补丁中的关键解释。我们的发现还表明,最显着的延迟原因归因于补丁管理过程中的协调延迟,并且大多数延迟发生在补丁部署阶段。为了减轻延迟,我们描述了研究从业者采用的一系列策略。这项研究是迈向理解延误的实际原因和脆弱性补丁管理中可能的缓解策略的第一步。我们的发现为从业者提供了有用的见解,以了解补丁管理过程中需要什么以及在哪里需要改进,并指导他们及时采取针对潜在攻击的行动。此外,我们的发现帮助研究人员投入努力设计和开发计算机支持的工具,以更好地支持及时的安全补丁管理过程。
Numerous security attacks that resulted in devastating consequences can be traced back to a delay in applying a security patch. Despite the criticality of timely patch application, not much is known about why and how delays occur when applying security patches in practice, and how the delays can be mitigated. Based on longitudinal data collected from 132 delayed patching tasks over a period of four years and observations of patch meetings involving eight teams from two organisations in the healthcare domain, and using quantitative and qualitative data analysis approaches, we identify a set of reasons relating to technology, people and organisation as key explanations that cause delays in patching. Our findings also reveal that the most prominent cause of delays is attributable to coordination delays in the patch management process and a majority of delays occur during the patch deployment phase. Towards mitigating the delays, we describe a set of strategies employed by the studied practitioners. This research serves as the first step towards understanding the practical reasons for delays and possible mitigation strategies in vulnerability patch management. Our findings provide useful insights for practitioners to understand what and where improvement is needed in the patch management process and guide them towards taking timely actions against potential attacks. Also, our findings help researchers to invest effort into designing and developing computer-supported tools to better support a timely security patch management process.