Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Softw 2021
DOI: 10.1145/3468264.3468595
|View full text |Cite
|
Sign up to set email alerts
|

A grounded theory of the role of coordination in software security patch management

Abstract: Several disastrous security attacks can be attributed to delays in patching software vulnerabilities. While researchers and practitioners have paid significant attention to automate vulnerabilities identification and patch development activities of software security patch management, there has been relatively little effort dedicated to gain an in-depth understanding of the socio-technical aspects, e.g., coordination of interdependent activities of the patching process and patching decisions, that may cause del… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

1
15
0

Year Published

2022
2022
2024
2024

Publication Types

Select...
3
3

Relationship

1
5

Authors

Journals

citations
Cited by 8 publications
(16 citation statements)
references
References 36 publications
1
15
0
Order By: Relevance
“…Concerning the coordination challenges, Dissanayake et. al [12] have proposed a grounded theory of the role of coordination in security patch management explaining the causes that create the need for coordinating in the security patch management process, constraints for effective coordination, breakdowns resulting from ineffective handling of the coordination causes and constraints, and mechanisms for managing the causes while mediating the constraints. Although several approaches have been proposed to improve the patch management process to reduce delays, the reasons why such delays occur and how to mitigate them remain unexplored.…”
Section: Background and Motivationmentioning
confidence: 99%
See 4 more Smart Citations
“…Concerning the coordination challenges, Dissanayake et. al [12] have proposed a grounded theory of the role of coordination in security patch management explaining the causes that create the need for coordinating in the security patch management process, constraints for effective coordination, breakdowns resulting from ineffective handling of the coordination causes and constraints, and mechanisms for managing the causes while mediating the constraints. Although several approaches have been proposed to improve the patch management process to reduce delays, the reasons why such delays occur and how to mitigate them remain unexplored.…”
Section: Background and Motivationmentioning
confidence: 99%
“…Concerning the complexity of patches, the patch interdependencies consisting of software, hardware, and firmware presented a major reason for delays in patch testing and deployment tasks. We identify that such complexities emerge from the existing dependencies in the source code, for example, function-level or library-level dependencies [12].…”
Section: 11mentioning
confidence: 99%
See 3 more Smart Citations