Skip to main content

Showing 1–1 of 1 results for author: Kaseorg, A

Searching in archive cs. Search in all archives.
.
  1. arXiv:0904.4058  [pdf, other

    cs.CR

    Security impact ratings considered harmful

    Authors: Jeff Arnold, Tim Abbott, Waseem Daher, Gregory Price, Nelson Elhage, Geoffrey Thomas, Anders Kaseorg

    Abstract: In this paper, we question the common practice of assigning security impact ratings to OS updates. Specifically, we present evidence that ranking updates by their perceived security importance, in order to defer applying some updates, exposes systems to significant risk. We argue that OS vendors and security groups should not focus on security updates to the detriment of other updates, but sho… ▽ More

    Submitted 26 April, 2009; originally announced April 2009.

    Comments: HotOS 2009