A Grounded Theory of the Role of Coordination in Software Security Patch Management

06/07/2021
by   Nesara Dissanayake, et al.
0

Several disastrous security attacks can be attributed to delays in patching software vulnerabilities. While researchers and practitioners have paid significant attention to automate vulnerabilities identification and patch development activities of software security patch management, there has been relatively little effort dedicated to gain an in-depth understanding of the socio-technical aspects, e.g., coordination of interdependent activities of the patching process and patching decisions, that may cause delays in applying security patches. We report on a Grounded Theory study of the role of coordination in security patch management. The reported theory consists of four inter-related dimensions, i.e., causes, breakdowns, constraints, and mechanisms. The theory explains the causes that define the need for coordination among interdependent software and hardware components and multiple stakeholders' decisions, the constraints that can negatively impact coordination, the breakdowns in coordination, and the potential corrective measures. This study provides potentially useful insights for researchers and practitioners who can carefully consider the needs of and devise suitable solutions for supporting the coordination of interdependencies involved in security patch management.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/18/2022

Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare Sector

Numerous security attacks that resulted in devastating consequences can ...
research
12/01/2020

Software Security Patch Management – A Systematic Literature Review of Challenges, Approaches, Tools and Practices

Context: Software security patch management purports to support the proc...
research
09/04/2022

An Empirical Study of Automation in Software Security Patch Management

Several studies have shown that automated support for different activiti...
research
07/24/2020

A Case Study on Software Vulnerability Coordination

Context: Coordination is a fundamental tenet of software engineering. Co...
research
07/07/2023

To Patch, or not To Patch? That is the Question: A Case Study of System Administrators' Online Collaborative Behaviour

System administrators, similar to end users, may delay or avoid software...
research
08/29/2023

Multilevel Semantic Embedding of Software Patches: A Fine-to-Coarse Grained Approach Towards Security Patch Detection

The growth of open-source software has increased the risk of hidden vuln...
research
11/12/2017

Coordination Technology for Active Support Networks: Context, Needfinding, and Design

Coordination is a key problem for addressing goal-action gaps in many hu...

Please sign up or login with your details

Forgot password? Click here to reset