首页> 外文会议>Software Reliability Engineering, 2009. ISSRE '09 >Optimal Security Patch Release Timing under Non-homogeneous Vulnerability-Discovery Processes
【24h】

Optimal Security Patch Release Timing under Non-homogeneous Vulnerability-Discovery Processes

机译:非均匀漏洞发现过程下的最佳安全补丁发布时间

获取原文

摘要

This paper proposes a patch management model with non-homogeneous vulnerability-discovery processes to find the optimal security patch release times. The proposed model is an extension of Cavusoglu et al. (2006, 2008) by applying non-homogeneous vulnerability-discovery processes which are based on a vulnerability life-cycle model, and provides the optimal schedule for security patch release times over a software life cycle by means of cost analysis. In numerical examples, we show that the optimal patch release policy becomes an aperiodic release strategy, and compare the minimum cost under the optimal policy with that under a periodic release strategy. In addition, based on opened vulnerability data, we illustrate the optimal security patch release policy for a real software product.
机译:本文提出了具有非均匀漏洞发现过程的补丁程序管理模型,以找到最佳的安全补丁程序发布时间。提出的模型是Cavusoglu等人的扩展。 (2006,2008),通过应用基于漏洞生命周期模型的非均匀漏洞发现流程,并通过成本分析为整个软件生命周期中的安全补丁发布时间提供了最佳计划。在数值示例中,我们表明最佳补丁发布策略成为非周期性发布策略,并将最佳策略下的最小成本与定期发布策略下的最小成本进行比较。此外,基于打开的漏洞数据,我们说明了针对实际软件产品的最佳安全补丁发布策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号