Title :
A cross-site patch management model and architecture design for large scale heterogeneous environment
Author :
Chang, Chuan-Wen ; Tsai, Dwen-Ren ; Tsai, Jui-Mi
Author_Institution :
Dept. of Inf. Manage., Chinese Culture Univ., Taipei, Taiwan
Abstract :
Many reports indicated that most damages caused by computer viruses and hackers´ attacks are due to management problems. Computing environments implementing well managed patch management processes with quick response mechanisms survive from most of serious attacks, such as My Doom and Sasser Warm attacks in 2004. Medium or large enterprises usually have heterogeneous computing environments. For example, a company may use an Apache server in a Linux-base PC as its Internet Web server, use an IBM AIX running IBM DB2 database system as a database server, and equip all employees with Windows-based PCs running Microsoft Office for their daily work. Also, employees might work at many different locations. In the enterprise patch management (PM) market today, there are very few complete off-the-shelf solutions. A systematic efficient PM process model with complete patch management activity process cycle and patching strategies was proposed. We also propose an automatic five-layer PM system application architecture supporting heterogeneous environment. The model, hopefully, makes enterprise patch process more efficient, and reduces the risks suffer from patch management challenges.
Keywords :
risk management; security of data; architecture design; cross-site patch management model; enterprise patch management market; information security; large scale heterogeneous environment; network management; patch management activity process cycle; patching strategy; Companies; Computer architecture; Computer hacking; Computer viruses; Database systems; Environmental management; Internet; Large-scale systems; Personal communication networks; Web server; Information Security; Network Management; Patch Management;
Conference_Titel :
Security Technology, 2005. CCST '05. 39th Annual 2005 International Carnahan Conference on
Print_ISBN :
0-7803-9245-0
DOI :
10.1109/CCST.2005.1594837