NWA
De Nationale Wetenschapsagenda

Theseus: Making patching happen

A core assumption underlying organizational security practices is that defenders are able to remediate known vulnerabilities in their systems in a timely fashion. Otherwise, attackers can just follow the breadcrumbs laid out by security advisories and exploit known weaknesses. This is indeed what happens in many large breaches. While progress has been made with patching of consumer systems, this does not translate to enterprises. They face a painful dilemma: patch too soon and incur potential downtime; patch too late and potentially get compromised by attacks. As a result, organizations take a long time to patch even critical security vulnerabilities. The central objective of THESEUS is to empower organizations to patch faster by radically changing the risk governance of patching through interdisciplinary breakthroughs at three interdependent levels:

* Systems: reducing risk of patching via new techniques in automatic vulnerability and patch triaging, as well as automatic patch generation with live update for cases where critical patches pose unacceptable availability risks.
* Enterprises: better quantifying risk of patching by assessing and aggregating the results of the patch triaging, as a way to estimate exploit likelihood in a coherent picture that accounts for different attacker models and functional impact.
* Governance: more effectively managing risks of patching by introducing incentive mechanisms via notifications and information sharing, sector-wide benchmarks of patching speed, and potentially legal instruments.

THESEUS aims to (1) bring advances from the lab to real-world settings by working with a large consortium of partners from healthcare and transportation who contribute people, data, and pilots; and (2) replace the status quo, as well as counterproductive solutions like mandatory patching, with a richer set of governance interventions across different levels.

Dossiernummer
NWA.1215.18.006
Projectleider
prof. dr. M.J.G. van Eeten
Hoofdorganisatie
Technische Universiteit Delft
Programma
Thema 2018 - Cybersecurity - Naar een veilig en betrouwbaar digitaal domein
Financieringsinstrument
NWA L2
Status
Lopend
Thema
Technologie en maatschappij
Consortium
Airfrance-KLM, Amsterdam UMC, CyberSprint, Cyberveilig Nederland, Deloitte, EuroControl, Gemeente Amsterdam, Gemeente Den Haag, KPN, Meander MC, NCSC, Philips Medical Systems, Rijkswaterstaat, Secura, Technische Universiteit Delft, Universiteit Tilburg, Vrije Universiteit Amsterdam en Z-CERT

Onderdeel van route

128 projecten
0 clustervragen
Afbeelding
Mensen kijken naar de zonsopkomst