Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
Skip to main content

Showing 1–4 of 4 results for author: Dissanayake, N

Searching in archive cs. Search in all archives.
.
  1. An Empirical Study of Automation in Software Security Patch Management

    Authors: Nesara Dissanayake, Asangi Jayatilaka, Mansooreh Zahedi, Muhammad Ali Babar

    Abstract: Several studies have shown that automated support for different activities of the security patch management process has great potential for reducing delays in installing security patches. However, it is also important to understand how automation is used in practice, its limitations in meeting real-world needs and what practitioners really need, an area that has not been empirically investigated i… ▽ More

    Submitted 3 September, 2022; originally announced September 2022.

    Comments: 13 pages, 2 figures

  2. arXiv:2202.09016  [pdf, other

    cs.SE cs.HC

    Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare Sector

    Authors: Nesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, M. Ali Babar

    Abstract: Numerous security attacks that resulted in devastating consequences can be traced back to a delay in applying a security patch. Despite the criticality of timely patch application, not much is known about why and how delays occur when applying security patches in practice, and how the delays can be mitigated. Based on longitudinal data collected from 132 delayed patching tasks over a period of fou… ▽ More

    Submitted 3 September, 2022; v1 submitted 17 February, 2022; originally announced February 2022.

    Comments: 28 pages, 10 figures

  3. A Grounded Theory of the Role of Coordination in Software Security Patch Management

    Authors: Nesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, Muhammad Ali Babar

    Abstract: Several disastrous security attacks can be attributed to delays in patching software vulnerabilities. While researchers and practitioners have paid significant attention to automate vulnerabilities identification and patch development activities of software security patch management, there has been relatively little effort dedicated to gain an in-depth understanding of the socio-technical aspects,… ▽ More

    Submitted 18 June, 2021; v1 submitted 7 June, 2021; originally announced June 2021.

    Comments: Accepted for publication at the 29th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE '21)

  4. arXiv:2012.00544  [pdf, other

    cs.SE

    Software Security Patch Management -- A Systematic Literature Review of Challenges, Approaches, Tools and Practices

    Authors: Nesara Dissanayake, Asangi Jayatilaka, Mansooreh Zahedi, M. Ali Babar

    Abstract: Context: Software security patch management purports to support the process of patching known software security vulnerabilities. Given the increasing recognition of the importance of software security patch management, it is important and timely to systematically review and synthesise the relevant literature on this topic. Objective: This paper aims at systematically reviewing the state of the a… ▽ More

    Submitted 19 August, 2021; v1 submitted 1 December, 2020; originally announced December 2020.

    Comments: 45 pages, 7 figures