Security Patch Management: Share the Burden or Share the Damage?
نویسندگان
چکیده
P management is a crucial component of information security management. An important problem within this context from a vendor’s perspective is to determine how to release patches to fix vulnerabilities in its software. From a firm’s perspective, the issue is how to update vulnerable systems with available patches. In this paper, we develop a game-theoretic model to study the strategic interaction between a vendor and a firm in balancing the costs and benefits of patch management. Our objective is to examine the consequences of time-driven release and update policies. We first study a centralized system in a benchmark scenario to find the socially optimal time-driven patch management. We show that the social loss is minimized when patch-release and update cycles are synchronized. Next, we consider a decentralized system in which the vendor determines its patch-release policy and the firm selects its patch-update policy in a Stackelberg framework, assuming that release and update policies are either time driven or event driven. We develop a sufficient condition that guarantees that a time-driven release by the vendor and a time-driven update by the firm is the equilibrium outcome for patch management. However, in this equilibrium, the patch-update cycle of the firm may not be synchronized with the patch-release cycle of the vendor, making it impossible to achieve the socially optimal patch management in the decentralized system. Therefore, we next examine cost sharing and liability as possible coordination mechanisms. Our analysis shows that cost sharing itself may achieve synchronization and social optimality. However, liability by itself cannot achieve social optimality unless patch-release and update cycles are already synchronized without introducing any liability. Our results also demonstrate that cost sharing and liability neither complement nor substitute each other. Finally, we show that an incentive-compatible contract on cost sharing can be designed to achieve coordination in case of information asymmetry.
منابع مشابه
Estimating the burden of occupational accidents using the DALY Index by economic activity type Case Study: Iran 2007-2017
Introduction: Sustainable development is human-centered and deserves health and safety. The rapid growth of industrialization, coupled with insufficient attention to safety principles, has led to an increase in the rate of accidents in developing countries. The purpose of this study was to estimate the years of life lost due to work-related accidents among workers covered by the National Social...
متن کاملSeparating indexes from data: a distributed scheme for secure database outsourcing
Database outsourcing is an idea to eliminate the burden of database management from organizations. Since data is a critical asset of organizations, preserving its privacy from outside adversary and untrusted server should be warranted. In this paper, we present a distributed scheme based on storing shares of data on different servers and separating indexes from data on a distinct server. Shamir...
متن کاملOptimizing Share of Fossil Energy Carriers in Energy-Intensive Industries of Iran
Management and optimization of energy consumption has been importantly considered by policy-makers in the field of energy and environment from the perspective of energy security and environmental considerations. In this study, nondominated sorting genetic algorithm (NSGAII) was applied to determine the optimal share of fossil energy sources for energy intensive industries of Iran including The ...
متن کاملOptimizing Share of Fossil Energy Carriers in Energy-Intensive Industries of Iran
Management and optimization of energy consumption has been importantly considered by policy-makers in the field of energy and environment from the perspective of energy security and environmental considerations. In this study, nondominated sorting genetic algorithm (NSGAII) was applied to determine the optimal share of fossil energy sources for energy intensive industries of Iran including The ...
متن کاملVoluntary Disclosure and Informational Content of Share Price: Evidence from Tehran Stock Exchange
The aim of this research was to determine the impact of voluntary information disclosure on informational content of share price. In this regard, future earnings response coefficient was used to determine the informational content of the share price about the future income information. Furthermore, share price synchronicity was used to evaluate the informational content of the share price about...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Management Science
دوره 54 شماره
صفحات -
تاریخ انتشار 2008