Monthly Patch Release Schedules: Do the Benefits Outweigh the Risks?

نویسندگان

  • Dominic White
  • Barry Irwin
چکیده

This paper provides a comprehensive discussion on patch schedules. This discussion occurs over two parts. The first analyses existing implementations of patch schedules with a focus on Microsoft’s monthly patch schedule. The arguments for patch schedules, namely increased patch quality and better planning within organisations are analysed and the impact of the type of disclosure investigated. It is concluded that in the case of delayed disclosure, where the vulnerability researcher privately discloses the vulnerability to the vendor allowing a patch to accompany the public disclosure, patch schedules provide significant benefits. However, in the case of instantaneous disclosure, where a vulnerability is disclosed directly to the public, as in the case of 0days, implementing a patch schedule significantly increases the risk to organisations waiting for a vendor patch. Some vendors already allow for ’out of band’ patches to be released, however the criteria for choosing when to release a patch ’out of band’ in unclear and often subjective. Additionally, involving the community in rapidly prototyping and testing patches will provide intrinsic benefits. The second part then builds on these findings to provide advice to vendors implementing patch schedules. First the type of disclosure is recommended as an objective and pertinent criteria for differentiating when a patch should be released per a schedule or as soon as possible. Next, effective mechanisms for implementing both types of patch release are discussed. The paper concludes that while patch schedules can provide significant benefits, vendors can still make many improvements based on recent examples to significantly improve their patch release methodology. Some of this work was undertaken in the Distributed Multimedia Centre of Excellence at Rhodes University, with financial support from Telkom SA, Business Connexion, Comverse, Verso Technologies, THRIP, and the National Research Foundation with additional financial assistance from the DAAD foundation hereby acknowledged. Some work was undertaken while in the employ of Deloitte and their contribution is acknowledged and appreciated.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Facemask Risks during the COVID-19 Crisis

Introduction: With the increasing severity of the COVID-19 epidemic, wearing a mask was recommended. This recommendation seems to have created concern among the public. Wearing a mask generally reduces the risk of virus and therefore potentially saves lives. In healthy populations, wearing a mask does not appear to cause any harmful physiological changes, and the potentially life-saving benefit...

متن کامل

Pro/con debate: Do the benefits of regionalized critical care delivery outweigh the risks of interfacility patient transport?

You are providing input in planning for critical care services to a large regional health authority. You are considering concentrating some critical care services into high-volume regional centres of excellence, as has been done in other fields of medicine. In your region, this would require several centres with differing levels of expertise that are geographically separated. Given there are in...

متن کامل

Perception of the risks and benefits of Bt eggplant by Indian farmers

Several researchers—most notably Lennart Sjoberg and his colleagues—have proposed that the moral aspects of risk provide a better explanation of risk perception than the psychometric paradigm or Cultural Theory, neither of which accounts for moral concerns. This study is possibly the first to assess empirically the perception of the risks and benefits of a transgenic food crop—transgenic Bt (Ba...

متن کامل

Mathematical Modeling of the Release of Active Ingredients from a Contraceptive Patch: Ortho Evra® as a Case StudY

Contraceptive patches have become a frequently used contraceptive method. We present a mathematical model that describes the serum concentration profiles of Norelgestromin (NGMN) and Ethinylestradiol (EE) released from the contraceptive patch Ortho Evra®. We propose a simple one-compartment model based on pharmacokinetics data reported in previous studies. The model assumes a time-dependent rel...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006