剖析企业为何犹豫打补丁,揭示安全与成本的矛盾
To Patch or Not to Patch: Motivations, Challenges, and Implications for Cybersecurity
- 从人性与组织角度分析补丁决策机制
- 发现资源不足、工具不可靠等五大拒打补丁原因
- 适合安全管理者与政策制定者阅读
随着技术深度融入社会,现代系统安全至关重要。补丁管理——即修复软件或硬件漏洞的更新——始终是持续讨论的话题。本文重新审视补丁问题,深入探讨组织与安全团队选择打补丁或不打补丁(显性或隐性)背后的动因。通过整合分析主流研究与行业文献,本文识别出关键动机:组织需求、与供应商的关系、法律与监管要求。同时发现显著的反动因:资源有限(如人力)、手动补丁管理困难、人为错误、劣质补丁、补丁管理工具不可靠,以及认为漏洞不会被利用的错觉。这些动机与反动因共同构成组织日常安全决策的复杂平衡。最后,论文讨论了研究启示与未来方向。
原文摘要 · Abstract (English)
As technology has become more embedded into our society, the security of modern-day systems is paramount. One topic which is constantly under discussion is that of patching, or more specifically, the installation of updates that remediate security vulnerabilities in software or hardware systems. This continued deliberation is motivated by complexities involved with patching; in particular, the various incentives and disincentives for organizations and their cybersecurity teams when deciding whether to patch. In this paper, we take a fresh look at the question of patching and critically explore why organizations and IT/security teams choose to patch or decide against it (either explicitly or due to inaction). We tackle this question by aggregating and synthesizing prominent research and industry literature on the incentives and disincentives for patching, specifically considering the human aspects in the context of these motives. Through this research, this study identifies key motivators such as organizational needs, the IT/security team's relationship with vendors, and legal and regulatory requirements placed on the business and its staff. There are also numerous significant reasons discovered for why the decision is taken not to patch, including limited resources (e.g., person-power), challenges with manual patch management tasks, human error, bad patches, unreliable patch management tools, and the perception that related vulnerabilities would not be exploited. These disincentives, in combination with the motivators above, highlight the difficult balance that organizations and their security teams need to maintain on a daily basis. Finally, we conclude by discussing implications of these findings and important future considerations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。