Death Is Not the End: a Longitudinal Study on the Impact of Automatic Updates on Container Vulnerability Lifespans
Simge Tekin, Octavian Suciu, Sungsu Kwag, Yonghwi Kwon, Tudor Dumitras
摘要
The emergence of immutable infrastructures such as container ecosystems has transformed how software is built, deployed, and maintained. In particular, patches that were traditionally delivered through in-place updates are now applied through image rebuilds and propagated through hierarchies of dependent images. Despite these substantial structural changes in patch delivery, the security impacts, such as the lifecycle of vulnerabilities and patching responsibilities in the software supply chain, remain understudied. Examining maintainer and user interactions across official Docker repositories, we find that maintainers often rely on automated patching of inherited vulnerabilities rather than intervening manually, while unclear maintenance timelines and responsibility boundaries impede remediation when automation halts. Building on these insights, we present the first longitudinal study of vulnerability lifespans in the Docker ecosystem, spanning six years. We analyze over 9,000 CVEs across 137 applications (from 756,313 images), and find that 78 % of inherited vulnerabilities remain unresolved 30 days after disclosure. The predominant cause of prolonged exposure is the breakdown of automated patch propagation due to upstream end-of-life (EOL) events, leaving 11 %-and up to in deeper dependency layers-of inherited vulnerabilities unpatched even when fixes exist. Based on these findings, we provide actionable recommendations to reduce the window of exposure to vulnerability exploits and release a tool to improve transparency. More broadly, our work provides empirical insights into the fragility of automated patch propagation in software supply chains, emphasizing the need for clear maintenance practices and accountability across dependency hierarchies.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar 等CCS 2017 · 被引用 196 次
- Asking for a Friend: Evaluating Response Biases in Security User StudiesElissa M. Redmiles, Ziyun Zhu, Sean Kross, Dhruv Kuchhal 等CCS 2018 · 被引用 65 次
- From Patching Delays to Infection Symptoms: Using Risk Profiles for an Early Discovery of Vulnerabilities Exploited in the WildChaowei Xiao, Armin Sarabi, Yang Liu, Bo Li 等USENIX Security 2018 · 被引用 31 次
- A different cup of TI? The added value of commercial threat intelligenceXander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr 等USENIX Security 2020
相关 Paper
- Dr. Docker: A Large-Scale Security Measurement of Docker Image EcosystemHequan Shi, Lingyun Ying, Libo Chen, Haixin Duan 等WWW 2025 · 被引用 1 次
- Unveiling the Characteristics and Impact of Security Patch EvolutionZifan Xie, Ming Wen, Zichao Wei, Hai JinASE 2024 · 被引用 2 次
- A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security FeaturesJessy Ayala, Yu-Jye Tung, Joshua GarciaUSENIX Security 2025
- Empirical Analysis of Vulnerabilities Life Cycle in Golang EcosystemJinchang Hu, Lyuye Zhang, Chengwei Liu, Sen Yang 等ICSE 2024 · 被引用 10 次
- Mitigating Persistence of Open-Source Vulnerabilities in Maven EcosystemLyuye Zhang, Chengwei Liu, Sen Chen, Zhengzi Xu 等ASE 2023 · 被引用 25 次
