Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare Sector
Nesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, Muhammad Ali Babar
摘要
Numerous security attacks that resulted in devastating consequences can be traced back to a delay in applying a security patch. Despite the criticality of timely patch application, not much is known about why and how delays occur when applying security patches in practice, and how the delays can be mitigated. Based on longitudinal data collected from 132 delayed patching tasks over a period of four years and observations of patch meetings involving eight teams from two organisations in the healthcare domain, and using quantitative and qualitative data analysis approaches, we identify a set of reasons relating to technology, people and organisation as key explanations that cause delays in patching. Our findings also reveal that the most prominent cause of delays is attributable to coordination delays in the patch management process and a majority of delays occur during the patch deployment phase. Towards mitigating the delays, we describe a set of strategies employed by the studied practitioners. This research serves as the first step toward understanding the practical reasons for delays and possible mitigation strategies in vulnerability patch management. Our findings provide useful insights for practitioners to understand what and where improvement is needed in the patch management process and guide them towards taking timely actions against potential attacks. Also, our findings help researchers to invest effort into designing and developing computer-supported tools to better support a timely security patch management process.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Not as easy as just update: Survey of System Administrators and Patching BehavioursAdam D. G. Jenkins, Linsen Liu, Maria K. Wolters, Kami VanieaCHI 2024 · 被引用 10 次
- An Empirical Study of Automation in Software Security Patch ManagementNesara Dissanayake, Asangi Jayatilaka, Mansooreh Zahedi, Muhammad Ali BabarASE 2022 · 被引用 7 次
- Patching Up: Stakeholder Experiences of Security Updates for Connected Medical DevicesLorenz Kustosch, Carlos Gañán, Michel van Eeten, Simon ParkinUSENIX Security 2025
- The (Un)usual Suspects - Studying Reasons for Lacking Updates in WordPressMaria Hellenthal, Lena Gotsche, Rafael Mrowczynski, Sarah Kugel 等NDSS 2025
- VeriBin: Adaptive Verification of Patches at the Binary LevelHongwei Wu, Jianliang Wu, Ruoyu Wu, Ayushi Sharma 等NDSS 2025
它引用的顶会 Paper4
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 被引用 116 次
- A grounded theory of the role of coordination in software security patch managementNesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, Muhammad Ali BabarFSE 2021 · 被引用 13 次
相关 Paper
- Speedrunning the Maze: Meeting Regulatory Patching Deadlines in a Large Enterprise EnvironmentGerbrand ten Napel, Michel van Eeten, Simon ParkinS&P 2025
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- No One Drinks From the Firehose: How Organizations Filter and Prioritize Vulnerability InformationStephanie de Smale, Rik van Dijk, Xander Bouwman, Jeroen van der Ham 等S&P 2023
- The Unpatchables: Why Municipalities Persist in Running Vulnerable HostsAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenUSENIX Security 2024 · 被引用 4 次
- DISPATCH: Unraveling Security Patches from Entangled Code ChangesShiyu Sun, Yunlong Xing, Xinda Wang, Shu Wang 等USENIX Security 2025
