论文标题

软件安全补丁管理中自动化的实证研究

An Empirical Study of Automation in Software Security Patch Management

论文作者

Dissanayake, Nesara, Jayatilaka, Asangi, Zahedi, Mansooreh, Babar, Muhammad Ali

论文摘要

几项研究表明,对安全补丁管理过程的不同活动的自动支持具有减少安装安全补丁的延迟的巨大潜力。但是,了解如何在实践中使用自动化,满足现实世界需求的局限性以及从业者真正需要的局限性,该领域尚未在现有的软件工程文献中进行经验研究。本文报告了一项实证研究,旨在使用与来自医疗保健领域三个不同组织的17位从业者进行半结构化访谈来调查安全补丁管理的不同方面。这些发现的重点是自动化在安全补丁管理中的作用,以提供实践中自动化状态的见解,当前自动化的局限性,如何增强自动化支持,以有效地满足从业者的需求以及人类在自动化过程中的作用。根据调查结果,我们提出了一系列建议,用于指导旨在为安全补丁管理提供自动支持的未来努力。

Several studies have shown that automated support for different activities of the security patch management process has great potential for reducing delays in installing security patches. However, it is also important to understand how automation is used in practice, its limitations in meeting real-world needs and what practitioners really need, an area that has not been empirically investigated in the existing software engineering literature. This paper reports an empirical study aimed at investigating different aspects of automation for security patch management using semi-structured interviews with 17 practitioners from three different organisations in the healthcare domain. The findings are focused on the role of automation in security patch management for providing insights into the as-is state of automation in practice, the limitations of current automation, how automation support can be enhanced to effectively meet practitioners' needs, and the role of the human in an automated process. Based on the findings, we have derived a set of recommendations for directing future efforts aimed at developing automated support for security patch management.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源