...
首页> 外文期刊>INFORMS journal on computing >Optimal Policies for Security Patch Management
【24h】

Optimal Policies for Security Patch Management

机译:安全补丁程序管理的最佳策略

获取原文
获取原文并翻译 | 示例
           

摘要

Effective patch management is critical to ensure the security of information systems that modern organizations count on today. Facing numerous patch releases from vendors, an information technology (IT) manager must weigh the costs of frequent patching against the security risks that can arise from delays in patch application. To this end, we develop a rigorous quantitative framework to analyze and compare several patching policies that are of practical interest. Our analyses of pure policies-policies that rely on a single metric such as elapsed time or patch severity level-show that certain policies are never optimal and no single policy may fit all information systems uniformly well. Depending on the context parameters, particularly the setup and business disruption costs for patching, either a time-based approach or an approach based on the cumulative severity level may be effective. To develop a more complete guideline for policy selection, we decipher hybrid policies that combine multiple metrics. Finally, we conduct extensive numerical experiments to verify the robustness of our analytical results. Overall, our paper establishes a comprehensive framework for analyzing various patching policies and furnishes useful insights for IT managers.
机译:有效的补丁程序管理对于确保现代组织如今所依赖的信息系统的安全至关重要。面对来自供应商的大量补丁程序发布,信息技术(IT)经理必须权衡频繁补丁程序的成本与补丁程序应用程序延迟所带来的安全风险。为此,我们开发了一个严格的定量框架来分析和比较一些实际感兴趣的修补策略。我们对依赖于单个度量标准(例如经过时间或补丁严重性级别)的纯策略的分析表明,某些策略永远不会是最优的,并且没有哪个策略可以很好地适合所有信息系统。根据上下文参数,尤其是修补程序的设置和业务中断成本,基于时间的方法或基于累积严重性级别的方法可能是有效的。为了制定更完整的策略选择指南,我们破译了结合了多种指标的混合策略。最后,我们进行了广泛的数值实验,以验证分析结果的可靠性。总体而言,本文建立了一个用于分析各种修补策略的综合框架,并为IT经理提供了有用的见解。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号