Several disastrous security attacks can be attributed to delays in patching software vulnerabilities. While researchers and practitioners have paid significant attention to automate vulnerabilities identification and patch development activities of software security patch management, there has been relatively little effort dedicated to gain an in-depth understanding of the socio-technical aspects, e.g., coordination of interdependent activities of the patching process and patching decisions, that may cause delays in applying security patches. We report on a Grounded Theory study of the role of coordination in security patch management. The reported theory consists of four inter-related dimensions, i.e., causes, breakdowns, constraints, and mechanisms. The theory explains the causes that define the need for coordination among interdependent software and hardware components and multiple stakeholders' decisions, the constraints that can negatively impact coordination, the breakdowns in coordination, and the potential corrective measures. This study provides potentially useful insights for researchers and practitioners who can carefully consider the needs of and devise suitable solutions for supporting the coordination of interdependencies involved in security patch management.
翻译:虽然研究人员和从业人员对软件安全补丁管理中脆弱性识别和补丁开发活动的自动化给予了极大关注,但为了深入了解社会技术方面,例如,协调补丁过程和补丁决定的相互依存活动,这可能造成安全补丁的延迟,相对没有作出多少努力。我们报告了关于协调在安全补丁管理中的作用的理论基础研究。报告理论包括四个相互关联的方面,即原因、故障、制约和机制。理论解释了为什么需要协调相互依存的软件和硬件组成部分以及多个利益攸关方的决定,哪些制约因素可能对协调、协调的中断和可能的纠正措施产生不利影响。这项研究为研究人员和从业人员提供了可能有用的见解,他们可以仔细考虑安全补丁管理中的各种需求,并设计适当的解决办法,以支持对安全补丁管理中相互依存关系的协调。