评估易受攻击软件系统的最佳补丁发布时间

Yogita Kansal, P. K. Kapur, Deepak Kumar
{"title":"评估易受攻击软件系统的最佳补丁发布时间","authors":"Yogita Kansal, P. K. Kapur, Deepak Kumar","doi":"10.1109/ICICCS.2016.7542358","DOIUrl":null,"url":null,"abstract":"Every failure in a software system demands for a repair or fixation process so as to deliver an intact system. In terms of IT industry, a patch intercepts users from getting exploited by the unknown complex defects which are termed as vulnerabilities. Many of the cyber attacks are due to the vulnerabilities and unacceptable management of the patches. One of the management issues is when one should apply a patch, since early patching results in instability aroused by bugs in the patches and behind patching may install malware in the system. The second key challenge is to maintain the quality of the software while releasing the patches. Despite of prevailing challenges, management has to deal with market potential. Thus in this paper, we have proposed a generalized framework to find a solution for mentioned problems. The framework identifies the optimal patch release time and optimal cost, and retains the reliability of the software. Further, the model elaborates the role of hacker, user and tester in different phases of a vulnerable software system.","PeriodicalId":389065,"journal":{"name":"2016 International Conference on Innovation and Challenges in Cyber Security (ICICCS-INBUSH)","volume":"35 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":"{\"title\":\"Assessing optimal patch release time for vulnerable software systems\",\"authors\":\"Yogita Kansal, P. K. Kapur, Deepak Kumar\",\"doi\":\"10.1109/ICICCS.2016.7542358\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Every failure in a software system demands for a repair or fixation process so as to deliver an intact system. In terms of IT industry, a patch intercepts users from getting exploited by the unknown complex defects which are termed as vulnerabilities. Many of the cyber attacks are due to the vulnerabilities and unacceptable management of the patches. One of the management issues is when one should apply a patch, since early patching results in instability aroused by bugs in the patches and behind patching may install malware in the system. The second key challenge is to maintain the quality of the software while releasing the patches. Despite of prevailing challenges, management has to deal with market potential. Thus in this paper, we have proposed a generalized framework to find a solution for mentioned problems. The framework identifies the optimal patch release time and optimal cost, and retains the reliability of the software. Further, the model elaborates the role of hacker, user and tester in different phases of a vulnerable software system.\",\"PeriodicalId\":389065,\"journal\":{\"name\":\"2016 International Conference on Innovation and Challenges in Cyber Security (ICICCS-INBUSH)\",\"volume\":\"35 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2016-02-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"6\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2016 International Conference on Innovation and Challenges in Cyber Security (ICICCS-INBUSH)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICICCS.2016.7542358\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 International Conference on Innovation and Challenges in Cyber Security (ICICCS-INBUSH)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICICCS.2016.7542358","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

摘要

软件系统中的每一个故障都需要一个修复或固定过程,以便交付一个完整的系统。在IT行业中,补丁可以阻止用户被未知的复杂缺陷利用,这些缺陷被称为漏洞。许多网络攻击都是由于补丁的漏洞和不可接受的管理。管理问题之一是何时应用补丁,因为早期修补会导致补丁中的错误引起不稳定,而后期修补可能会在系统中安装恶意软件。第二个关键挑战是在发布补丁的同时保持软件的质量。尽管面临着普遍的挑战,但管理层必须应对市场潜力。因此,在本文中,我们提出了一个广义的框架来寻找上述问题的解决方案。该框架确定了最优补丁发布时间和最优成本,并保持了软件的可靠性。该模型进一步阐述了黑客、用户和测试人员在易受攻击软件系统不同阶段的作用。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Assessing optimal patch release time for vulnerable software systems
Every failure in a software system demands for a repair or fixation process so as to deliver an intact system. In terms of IT industry, a patch intercepts users from getting exploited by the unknown complex defects which are termed as vulnerabilities. Many of the cyber attacks are due to the vulnerabilities and unacceptable management of the patches. One of the management issues is when one should apply a patch, since early patching results in instability aroused by bugs in the patches and behind patching may install malware in the system. The second key challenge is to maintain the quality of the software while releasing the patches. Despite of prevailing challenges, management has to deal with market potential. Thus in this paper, we have proposed a generalized framework to find a solution for mentioned problems. The framework identifies the optimal patch release time and optimal cost, and retains the reliability of the software. Further, the model elaborates the role of hacker, user and tester in different phases of a vulnerable software system.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信