首页 | 本学科首页   官方微博 | 高级检索  
     检索      


Information security trade-offs and optimal patching policies
Authors:Christos Ioannidis  David Pym
Institution:a University of Bath, Department of Economics, Bath BA2 7AY, England, UK
b University of Aberdeen, School of Natural and Computing Sciences, King’s College, Aberdeen AB24 3UE, Scotland, UK
c Business School, University of Aberdeen, King’s College, Aberdeen AB24 3QY, Scotland, UK
Abstract:We develop and simulate a basic mathematical model of the costly deployment of software patches in the presence of trade-offs between confidentiality and availability. The model incorporates representations of the key aspects of the system architecture, the managers’ preferences, and the stochastic nature of the threat environment. Using the model, we compute the optimal frequencies for regular and irregular patching, for both networks and clients, for two example types of organization, military and financial. Such examples are characterized by their constellations of parameters. Military organizations, being relatively less cost-sensitive, tend to apply network patches upon their arrival. The relatively high cost of applying irregular client patches leads both types of organization to avoid deployment upon arrival.
Keywords:Information security  Optimal policy  Risk reduction  Stochastic processes
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号