Visible to the public Human Behavior and Cyber Vulnerabilities - July 2014

Public Audience
Purpose: To highlight project progress. Information is generally at a higher level which is accessible to the interested public. All information contained in the report (regions 1-3) is a Government Deliverable/CDRL.

PI(s): VS Subrahmanian
Researchers: Richard Johnson, Tudor Dumitras, Marshini Chetty, Aditya Prakash

 

HARD PROBLEM(S) ADDRESSED

This refers to Hard Problems, released November 2012.

Understanding and Accounting for Human Behavior

Project synopsis

When a vulnerability is exploited, software vendors often release patches fixing the vulnerability. However, our prior research has shown that some vulnerabilities continue to be exploited more than four years after their disclosure. Why? We posit that there are both technical and sociological reasons for this. On the technical side, it is unclear how quickly security patches are disseminated, and how long it takes to patch all the vulnerable hosts on the Internet. On the sociological side, users/administrators may decide to delay the deployment of security patches. Our goal in this task is to validate and quantify these explanations. Specifically, we seek to characterize the rate of vulnerability patching, and to determine the factors—both technical and sociological—that influence the rate of applying patches. 

 

PUBLICATIONS
Report papers written as a results of this research. If accepted by or submitted to a journal, which journal. If presented at a conference, which conference.

 

ACCOMPLISHMENT HIGHLIGHTS