Monthly Patch Release Schedules: Do the Benefits Outweigh the Risks?
نویسندگان
چکیده
This paper provides a comprehensive discussion on patch schedules. This discussion occurs over two parts. The first analyses existing implementations of patch schedules with a focus on Microsoft’s monthly patch schedule. The arguments for patch schedules, namely increased patch quality and better planning within organisations are analysed and the impact of the type of disclosure investigated. It is concluded that in the case of delayed disclosure, where the vulnerability researcher privately discloses the vulnerability to the vendor allowing a patch to accompany the public disclosure, patch schedules provide significant benefits. However, in the case of instantaneous disclosure, where a vulnerability is disclosed directly to the public, as in the case of 0days, implementing a patch schedule significantly increases the risk to organisations waiting for a vendor patch. Some vendors already allow for ’out of band’ patches to be released, however the criteria for choosing when to release a patch ’out of band’ in unclear and often subjective. Additionally, involving the community in rapidly prototyping and testing patches will provide intrinsic benefits. The second part then builds on these findings to provide advice to vendors implementing patch schedules. First the type of disclosure is recommended as an objective and pertinent criteria for differentiating when a patch should be released per a schedule or as soon as possible. Next, effective mechanisms for implementing both types of patch release are discussed. The paper concludes that while patch schedules can provide significant benefits, vendors can still make many improvements based on recent examples to significantly improve their patch release methodology. Some of this work was undertaken in the Distributed Multimedia Centre of Excellence at Rhodes University, with financial support from Telkom SA, Business Connexion, Comverse, Verso Technologies, THRIP, and the National Research Foundation with additional financial assistance from the DAAD foundation hereby acknowledged. Some work was undertaken while in the employ of Deloitte and their contribution is acknowledged and appreciated.
منابع مشابه
Facemask Risks during the COVID-19 Crisis
Introduction: With the increasing severity of the COVID-19 epidemic, wearing a mask was recommended. This recommendation seems to have created concern among the public. Wearing a mask generally reduces the risk of virus and therefore potentially saves lives. In healthy populations, wearing a mask does not appear to cause any harmful physiological changes, and the potentially life-saving benefit...
متن کاملPro/con debate: Do the benefits of regionalized critical care delivery outweigh the risks of interfacility patient transport?
You are providing input in planning for critical care services to a large regional health authority. You are considering concentrating some critical care services into high-volume regional centres of excellence, as has been done in other fields of medicine. In your region, this would require several centres with differing levels of expertise that are geographically separated. Given there are in...
متن کاملDo the Health Benefits of Cycling Outweigh the Risks? Os benefícios à saúde em andar de bicicleta superam os riscos?
Non-profit academic project, developed under the open access initiative
متن کاملPerception of the risks and benefits of Bt eggplant by Indian farmers
Several researchers—most notably Lennart Sjoberg and his colleagues—have proposed that the moral aspects of risk provide a better explanation of risk perception than the psychometric paradigm or Cultural Theory, neither of which accounts for moral concerns. This study is possibly the first to assess empirically the perception of the risks and benefits of a transgenic food crop—transgenic Bt (Ba...
متن کاملMathematical Modeling of the Release of Active Ingredients from a Contraceptive Patch: Ortho Evra® as a Case StudY
Contraceptive patches have become a frequently used contraceptive method. We present a mathematical model that describes the serum concentration profiles of Norelgestromin (NGMN) and Ethinylestradiol (EE) released from the contraceptive patch Ortho Evra®. We propose a simple one-compartment model based on pharmacokinetics data reported in previous studies. The model assumes a time-dependent rel...
متن کامل