Security impact ratings considered harmful

dc.creatorArnold, Jeff
dc.creatorAbbott, Tim
dc.creatorDaher, Waseem
dc.creatorPrice, Gregory
dc.creatorElhage, Nelson
dc.creatorThomas, Geoffrey
dc.creatorKaseorg, Anders
dc.date2009-04-26
dc.date.accessioned2026-07-07T13:08:53Z
dc.date.available2026-07-07T13:08:53Z
dc.descriptionIn this paper, we question the common practice of assigning security impact ratings to OS updates. Specifically, we present evidence that ranking updates by their perceived security importance, in order to defer applying some updates, exposes systems to significant risk. We argue that OS vendors and security groups should not focus on security updates to the detriment of other updates, but should instead seek update technologies that make it feasible to distribute updates for all disclosed OS bugs in a timely manner.
dc.descriptionHotOS 2009
dc.identifierhttps://arxiv.org/abs/0904.4058
dc.identifierhttp://arxiv.org/abs/0904.4058
dc.identifier.urihttp://salesiana.dossiersoluciones.com/handle/123456789/228562
dc.subjectCryptography and Security
dc.titleSecurity impact ratings considered harmful
dc.typetext

Files

Collections