亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

Security Patch Management: Share the Burden or Share the Damage?

小贩 背景(考古学) 斯塔克伯格竞赛 计算机科学 水准点(测量) 博弈论 业务 风险分析(工程) 经济 微观经济学 营销 大地测量学 生物 古生物学 地理
作者
Hasan Cavusoglu,Huseyin Cavusoglu,Jun Zhang
出处
期刊:Management Science [Institute for Operations Research and the Management Sciences]
卷期号:54 (4): 657-670 被引量:151
标识
DOI:10.1287/mnsc.1070.0794
摘要

Patch management is a crucial component of information security management. An important problem within this context from a vendor's perspective is to determine how to release patches to fix vulnerabilities in its software. From a firm's perspective, the issue is how to update vulnerable systems with available patches. In this paper, we develop a game-theoretic model to study the strategic interaction between a vendor and a firm in balancing the costs and benefits of patch management. Our objective is to examine the consequences of time-driven release and update policies. We first study a centralized system in a benchmark scenario to find the socially optimal time-driven patch management. We show that the social loss is minimized when patch-release and update cycles are synchronized. Next, we consider a decentralized system in which the vendor determines its patch-release policy and the firm selects its patch-update policy in a Stackelberg framework, assuming that release and update policies are either time driven or event driven. We develop a sufficient condition that guarantees that a time-driven release by the vendor and a time-driven update by the firm is the equilibrium outcome for patch management. However, in this equilibrium, the patch-update cycle of the firm may not be synchronized with the patch-release cycle of the vendor, making it impossible to achieve the socially optimal patch management in the decentralized system. Therefore, we next examine cost sharing and liability as possible coordination mechanisms. Our analysis shows that cost sharing itself may achieve synchronization and social optimality. However, liability by itself cannot achieve social optimality unless patch-release and update cycles are already synchronized without introducing any liability. Our results also demonstrate that cost sharing and liability neither complement nor substitute each other. Finally, we show that an incentive-compatible contract on cost sharing can be designed to achieve coordination in case of information asymmetry.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
27秒前
云7发布了新的文献求助10
34秒前
who完成签到,获得积分10
40秒前
1分钟前
天天快乐应助科研通管家采纳,获得10
1分钟前
托尔斯泰发布了新的文献求助10
1分钟前
托尔斯泰完成签到,获得积分10
1分钟前
紫气东来完成签到,获得积分10
1分钟前
silence完成签到 ,获得积分10
1分钟前
耍酷的鹰完成签到,获得积分10
1分钟前
zh完成签到,获得积分10
2分钟前
大个应助外向的逊采纳,获得10
2分钟前
炙热雅琴发布了新的文献求助10
3分钟前
3分钟前
碳酸芙兰完成签到,获得积分10
3分钟前
3分钟前
汉堡包应助且行丶且努力采纳,获得10
3分钟前
3分钟前
lyy发布了新的文献求助10
3分钟前
李爱国应助贝果采纳,获得10
3分钟前
连玉完成签到,获得积分10
4分钟前
4分钟前
4分钟前
且行丶且努力完成签到,获得积分10
4分钟前
4分钟前
WWW完成签到 ,获得积分10
4分钟前
5分钟前
5分钟前
5分钟前
沉静连虎完成签到,获得积分10
5分钟前
joeqin完成签到,获得积分10
5分钟前
ZanE完成签到,获得积分10
5分钟前
落羽无尘1006完成签到,获得积分10
5分钟前
漂亮的孤丹完成签到 ,获得积分10
5分钟前
5分钟前
平淡如天完成签到,获得积分10
5分钟前
Xuer完成签到,获得积分10
5分钟前
6分钟前
欣欣完成签到,获得积分20
6分钟前
呱呱完成签到,获得积分10
6分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Picture this! Including first nations fiction picture books in school library collections 2000
The Cambridge History of China: Volume 4, Sui and T'ang China, 589–906 AD, Part Two 1500
Cowries - A Guide to the Gastropod Family Cypraeidae 1200
ON THE THEORY OF BIRATIONAL BLOWING-UP 666
Signals, Systems, and Signal Processing 610
Pulse width control of a 3-phase inverter with non sinusoidal phase voltages 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6389188
求助须知:如何正确求助?哪些是违规求助? 8203868
关于积分的说明 17358575
捐赠科研通 5442743
什么是DOI,文献DOI怎么找? 2878086
邀请新用户注册赠送积分活动 1854400
关于科研通互助平台的介绍 1697925