首页> 外文会议>International Conference on Passive and Active Measurement >Our (in)Secure Web: Understanding Update Behavior of Websites and Its Impact on Security
【24h】

Our (in)Secure Web: Understanding Update Behavior of Websites and Its Impact on Security

机译:我们(in)安全网页:了解网站的更新行为及其对安全的影响

获取原文

摘要

Software updates take an essential role in keeping IT environments secure. If service providers delay or do not install updates, it can cause unwanted security implications for their environments. This paper conducts a large-scale measurement study of the update behavior of websites and their utilized software stacks. Across 18 months, we analyze over 5.6M websites and 246 distinct client- and server-side software distributions. We found that almost all analyzed sites use outdated software. To understand the possible security implications of outdated software, we analyze the potential vulnerabilities that affect the utilized software. We show that software components are getting older and more vulnerable because they are not updated. We find that 95 % of the analyzed websites use at least one product for which a vulnerability existed.
机译:软件更新在保持IT环境安全方面取得重要作用。 如果服务提供商延迟或不安装更新,则可能对其环境造成不必要的安全影响。 本文对网站的更新行为及其利用的软件堆栈进行了大规模的测量研究。 在18个月,我们分析了5.6米的网站和246个独特的客户端和服务器端软件分布。 我们发现几乎所有分析的网站都使用过时的软件。 要了解过时软件可能的安全影响,我们分析了影响利用软件的潜在漏洞。 我们显示软件组件越来越旧,因为它们未更新。 我们发现95%的分析网站使用至少一个漏洞存在的产品。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号