Timing the Application of Security Patches for Optimal Uptime

From: Crispin Cowan (crispin@wirex.com)
Date: 11/10/02


Date: Sun, 10 Nov 2002 08:11:39 -0800
From: Crispin Cowan <crispin@wirex.com>
To: "BUGTRAQ@SECURITYFOCUS.COM" <BUGTRAQ@SECURITYFOCUS.COM>, secpapers@securityfocus.com

This paper has been published at the USENIX LISA 2002 conference
<http://www.usenix.org/events/lisa02/>, and is available for download
here <http://wirex.com/%7Ecrispin/time-to-patch-usenix-lisa02.ps.gz>.

         Timing the Application of Security Patches for Optimal Uptime

Steve Beattie, Seth Arnold, Crispin Cowan, Perry Wagle, and Chris Wright
            WireX Communications, Inc. http://wirex.com
                                      and
                                Adam Shostack
                 Informed Security http://www.informedsecurity.com

     Security vulnerabilities are discovered, become publicly known, get
     exploited by attackers, and patches come out. When should one apply
     security patches? Patch too soon, and you may suffer from
     instability induced by bugs in the patches. Patch too late, and you
     get hacked by attackers exploiting the vulnerability. We explore
     the factors affecting when it is best to apply security patches,
     providing both mathematical models of the factors affecting when to
     patch, and collecting empirical data to give the model practical
     value. We conclude with a model that we hope will help provide a
     formal foundation for when the practitioner should apply security
     updates.

Crispin

-- 
Crispin Cowan, Ph.D.
Chief Scientist, WireX                      http://wirex.com/~crispin/
Security Hardened Linux Distribution:       http://immunix.org
Available for purchase: http://wirex.com/Products/Immunix/purchase.html
			    Just say ".Nyet"



Relevant Pages

  • RE: IIS on 443 replaced by serv-u
    ... It sounds like your system was compromised before installing the patch. ... More information on creating slip-streamed installs of Windows can ... Download the Security Patch Management Guide: ... It's important to not that not all security patches are offered by the ...
    (microsoft.public.inetserver.iis.security)
  • Re: Patches not included in SMS 2003 SP1 software update
    ... >> 1) Why are they not included in Software updates? ... This doesn't look like a security patch to me, ... The patch mechanisms only include security patches. ...
    (microsoft.public.sms.admin)
  • Re: Use this patch immediately
    ... >> to be posted from microsoft corp. when I attempt to download the patch ... >> to download their latest security patch I get the same message. ... Are these security patches really needed? ... > an email is asking to become another zombie. ...
    (microsoft.public.security.virus)
  • RE: Is VMS losing the Financial Sector, also?
    ... we still have to apply security patches. ... SuSE Linux. ... "Patch Tuesday" is NOT ...
    (comp.os.vms)
  • VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4
    ... Patch URL: http://www.vmware.com/download/esx/esx-253-200610-patch.html ... Updated package addresses several security issues. ... Common Vulnerabilities and Exposures project assigned ... VMware Security Response Policy ...
    (Bugtraq)