An Empirical Study of Automation in Software Security Patch Management
Nesara Dissanayake, Asangi Jayatilaka, Mansooreh Zahedi, Muhammad Ali Babar
Abstract
Several studies have shown that automated support for different activities of the security patch management process has great potential for reducing delays in installing security patches. However, it is also important to understand how automation is used in practice, its limitations in meeting real-world needs and what practitioners really need, an area that has not been empirically investigated in the existing software engineering literature. This paper reports an empirical study aimed at investigating different aspects of automation for security patch management using semi-structured interviews with 17 practitioners from three different organisations in the healthcare domain. The findings are focused on the role of automation in security patch management for providing insights into the as-is state of automation in practice, the limitations of current automation, how automation support can be enhanced to effectively meet practitioners' needs, and the role of the human in an automated process. Based on the findings, we have derived a set of recommendations for directing future efforts aimed at developing automated support for security patch management. CCS CONCEPTS • Security and privacy → Software security engineering; Vulnerability management; • Software and its engineering → Software post-development issues.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1ba52b99-d88d-48e3-840e-4de17732b841Cited by top-tier papers3
- Towards More Practical Automation of Vulnerability AssessmentShengyi Pan, Lingfeng Bao, Jiayuan Zhou, Xing Hu et al.ICSE 2024 · 8 citations
- Patching Up: Stakeholder Experiences of Security Updates for Connected Medical DevicesLorenz Kustosch, Carlos Gañán, Michel van Eeten, Simon ParkinUSENIX Security 2025
- Answer Is Cheap, Show Me the Evidence! Augmenting Automated Vulnerability Assessment with EvidenceShengyi Pan, Zelong Zheng, Jiayuan Zhou, Xing Hu et al.ISSTA 2026
Builds on5
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 116 citations
- Automated Patch Correctness Assessment: How Far are We?Shangwen Wang, Ming Wen, Bo Lin, Hongjun Wu et al.ASE 2020 · 77 citations
- Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare SectorNesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, Muhammad Ali BabarCSCW 2022 · 18 citations
- A grounded theory of the role of coordination in software security patch managementNesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, Muhammad Ali BabarFSE 2021 · 13 citations
- Efficient state synchronisation in model-based testing through reinforcement learningUraz Cengiz Türker, Robert M. Hierons, Mohammad Reza Mousavi, Ivan Yu. TyukinASE 2021 · 7 citations
Related papers
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 84 citations
- Software Architecture in Practice: Challenges and OpportunitiesZhiyuan Wan, Yun Zhang, Xin Xia, Yi Jiang et al.FSE 2023 · 29 citations
- "False negative - that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security TestingAmit Seal Ami, Kevin Moran, Denys Poshyvanyk, Adwait NadkarniS&P 2024 · 40 citations
- Software Vulnerability Management in the Era of Artificial Intelligence: An Industry PerspectiveM. Mehdi Kholoosi, Triet Huynh Minh Le, M. Ali BabarICSE 2026
- An Empirical Study on Software Bill of Materials: Where We Stand and the Road AheadBoming Xia, Tingting Bi, Zhenchang Xing, Qinghua Lu et al.ICSE 2023 · 82 citations
