Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare Sector

02/18/2022
by   Nesara Dissanayake, et al.
0

Numerous security attacks that resulted in devastating consequences can be traced back to a delay in applying a security patch. Despite the criticality of timely patch application, not much is known about why and how delays occur when applying security patches in practice, and how the delays can be mitigated. Based on longitudinal data collected from 132 delayed patching tasks over a period of four years and observations of patch meetings involving eight teams from two organisations in the healthcare domain, and using quantitative and qualitative data analysis approaches, we identify a set of reasons relating to technology, people and organisation as key explanations that cause delays in patching. Our findings also reveal that the most prominent cause of delays is attributable to coordination delays in the patch management process and a majority of delays occur during the patch deployment phase. Towards mitigating the delays, we describe a set of strategies employed by the studied practitioners. This research serves as the first step towards understanding the practical reasons for delays and possible mitigation strategies in vulnerability patch management. Our findings provide useful insights for practitioners to understand what and where improvement is needed in the patch management process and guide them towards taking timely actions against potential attacks. Also, our findings help researchers to invest effort into designing and developing computer-supported tools to better support a timely security patch management process.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/07/2021

A Grounded Theory of the Role of Coordination in Software Security Patch Management

Several disastrous security attacks can be attributed to delays in patch...
research
09/04/2022

An Empirical Study of Automation in Software Security Patch Management

Several studies have shown that automated support for different activiti...
research
07/07/2023

To Patch, or not To Patch? That is the Question: A Case Study of System Administrators' Online Collaborative Behaviour

System administrators, similar to end users, may delay or avoid software...
research
05/01/2020

Jacks of All Trades, Masters Of None: Addressing Distributional Shift and Obtrusiveness via Transparent Patch Attacks

We focus on the development of effective adversarial patch attacks and –...
research
08/23/2023

Network Navigation with Online Delays is PSPACE-complete

In public transport networks disruptions may occur and lead to travel de...
research
08/31/2023

Causal Analysis of First-Year Course Approval Delays in an Engineering Major Through Inference Techniques

The study addresses the problem of delays in the approval of first-year ...
research
05/25/2019

Propagation and Decay of Injected One-Off Delays on Clusters: A Case Study

Analytic, first-principles performance modeling of distributed-memory ap...

Please sign up or login with your details

Forgot password? Click here to reset