技术系统企业风险管理:漏洞特征作为利用程序发布驱动因素的探索性实证分析

Managing Enterprise Risks of Technological Systems: An Exploratory Empirical Analysis of Vulnerability Characteristics as Drivers of Exploit Publication*

DECISION SCIENCES · 2016
被引 15
人大 AABS 3

中文导读

分析了软件漏洞特征与利用程序发布时间的关系,发现基于利用发布可能性的优先级排序能帮助技术管理者更有效地分配补丁资源,减少攻击损失。

Abstract

Enterprises experience opportunistic exploits targeted at vulnerable technology. Vulnerabilities in software-based applications, service systems, enterprise platforms, and supply chains are discovered and disclosed on an alarmingly regular basis. A necessary enterprise risk management task concerns identifying and patching vulnerabilities. Yet it is a costly affair to develop and deploy patches to alleviate risk and prevent damage from exploit attacks. Given the limited resources available, technology producers and users must identify priorities for such tasks. When not overlooked, vulnerability-patching tasks often are prioritized based on vulnerability disclosure dates, thus vulnerabilities disclosed earlier usually have patches developed and deployed earlier. We suggest priorities also should focus on time-dependent likelihoods of exploits getting published. We analyze data on software exploits to identify factors associated with the duration between a vulnerability discovery date and the date when an exploit is publicly available, a time window for patching before exploit attack levels may escalate. Actively prioritizing vulnerability patching based on likelihoods of exploit publication may help lessen losses due to exploit attacks. Technology managers might apply the insights to better estimate relative risk levels, and better prioritize protection efforts toward vulnerabilities having higher risk of earlier exploitation.

企业风险管理软件漏洞网络安全漏洞利用实证分析