pith. sign in

arxiv: 0904.4058 · v1 · submitted 2009-04-26 · 💻 cs.CR

Security impact ratings considered harmful

classification 💻 cs.CR
keywords updatessecurityimpactratingsshouldapplyingargueassigning
0
0 comments X
read the original abstract

In this paper, we question the common practice of assigning security impact ratings to OS updates. Specifically, we present evidence that ranking updates by their perceived security importance, in order to defer applying some updates, exposes systems to significant risk. We argue that OS vendors and security groups should not focus on security updates to the detriment of other updates, but should instead seek update technologies that make it feasible to distribute updates for all disclosed OS bugs in a timely manner.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.