{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T07:18:48Z","timestamp":1784099928110,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":63,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T00:00:00Z","timestamp":1665360000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,10,10]]},"DOI":"10.1145\/3551349.3556969","type":"proceedings-article","created":{"date-parts":[[2023,1,5]],"date-time":"2023-01-05T20:43:54Z","timestamp":1672951434000},"page":"1-13","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["An Empirical Study of Automation in Software Security Patch Management"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2873-137X","authenticated-orcid":false,"given":"Nesara","family":"Dissanayake","sequence":"first","affiliation":[{"name":"CREST \u2013 Centre for Research on Engineering Software Technologies, The University of Adelaide, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2051-030X","authenticated-orcid":false,"given":"Asangi","family":"Jayatilaka","sequence":"additional","affiliation":[{"name":"CREST \u2013 Centre for Research on Engineering Software Technologies, The University of Adelaide, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6276-9956","authenticated-orcid":false,"given":"Mansooreh","family":"Zahedi","sequence":"additional","affiliation":[{"name":"The University of Melbourne, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9696-3626","authenticated-orcid":false,"given":"Muhammad Ali","family":"Babar","sequence":"additional","affiliation":[{"name":"CREST \u2013 Centre for Research on Engineering Software Technologies, The University of Adelaide, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,1,5]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2022. Ivanti. Retrieved February 17 2022 from https:\/\/www.ivanti.com\/"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","unstructured":"A. Al-Ayed S.M. Furnell D. Zhao and P.S. Dowland. 2005. An automated framework for managing security vulnerabilities. Information management & computer security 13 2 (2005) 156\u2013166. https:\/\/doi.org\/10.1108\/09685220510589334","DOI":"10.1108\/09685220510589334"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3290605.3300233"},{"key":"e_1_3_2_1_4_1","volume-title":"Vulnus: Visual vulnerability analysis for network security","author":"Angelini Marco","year":"2018","unstructured":"Marco Angelini, Graziano Blasilli, Tiziana Catarci, Simone Lenti, and Giuseppe Santucci. 2018. Vulnus: Visual vulnerability analysis for network security. IEEE transactions on visualization and computer graphics 25, 1(2018), 183\u2013192."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cola.2018.12.007"},{"key":"e_1_3_2_1_6_1","volume-title":"Retrieved","year":"2022","unstructured":"Apache. 2022. Apache Log4j. Retrieved April 21, 2022 from https:\/\/logging.apache.org\/log4j\/2.x\/security.html"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3417056"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1835804.1835821"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2043556.2043567"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCST.2005.1594837"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1323293.1294283"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-17081-3_4"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.24251\/HICSS.2019.034"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243794"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2021.106771"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468595"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3555087"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICAC.2004.1301353"},{"key":"e_1_3_2_1_19_1","volume-title":"Retrieved","author":"Executive Chief\u00a0Healthcare","year":"2022","unstructured":"Chief\u00a0Healthcare Executive. 2022. Cyberattacks in healthcare surged last year, and 2022 could be even worse. Retrieved April 24, 2022 from https:\/\/www.chiefhealthcareexecutive.com\/view\/cyberattacks-in-healthcare-surged-last-year-and-2022-could-be-even-worse"},{"key":"e_1_3_2_1_20_1","volume-title":"Retrieved","author":"Center for Internet Security\u00a0(CIS).","year":"2022","unstructured":"Center for Internet Security\u00a0(CIS). 2022. Cyber Attacks: In the Healthcare Sector. Retrieved April 24, 2022 from https:\/\/www.cisecurity.org\/insights\/blog\/cyber-attacks-in-the-healthcare-sector"},{"key":"e_1_3_2_1_21_1","volume-title":"The Discovery of Grounded Theory: Strategies for Qualitative Research. Aldine Transaction","author":"Glaser G.","unstructured":"Barney\u00a0G. Glaser and Anselmo\u00a0L. Strauss. 1967. The Discovery of Grounded Theory: Strategies for Qualitative Research. Aldine Transaction, Chicago."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/381694.378798"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS.2012.6211988"},{"key":"e_1_3_2_1_24_1","unstructured":"QSR International. 2022. Nvivo qualitative data analysis software. https:\/\/www.qsrinternational.com\/nvivo-qualitative-data-analysis-software\/home"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"Chadni Islam Victor Prokhorenko and Muhammad\u00a0Ali Babar. 2022. Runtime Software Patching: Taxonomy Survey and Future Directions. arXiv preprint arXiv:2203.12132(2022). https:\/\/arxiv.org\/pdf\/2203.12132.pdf","DOI":"10.2139\/ssrn.4062747"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00015"},{"key":"e_1_3_2_1_27_1","unstructured":"Ece Kamar. 2016. Directions in Hybrid Intelligence: Complementing AI Systems with Human Intelligence. In IJCAI. 4070\u20134073."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SERE.2013.31"},{"key":"e_1_3_2_1_29_1","volume-title":"2016 USENIX Annual Technical Conference (USENIX ATC 16)","author":"Kashyap Sanidhya","year":"2016","unstructured":"Sanidhya Kashyap, Changwoo Min, Byoungyoung Lee, Taesoo Kim, and Pavel Emelyanov. 2016. Instant {OS} Updates via Userspace {Checkpoint-and-Restart}. In 2016 USENIX Annual Technical Conference (USENIX ATC 16). 605\u2013619."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11277-015-3162-z"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11227-019-02946-y"},{"key":"e_1_3_2_1_32_1","unstructured":"Vivian Lai Samuel Carton and Chenhao Tan. 2020. Harnessing explanations to bridge ai and humans. arXiv preprint arXiv:2003.07370(2020). https:\/\/arxiv.org\/pdf\/2003.07370"},{"key":"e_1_3_2_1_33_1","volume-title":"Keepers of the Machines: Examining How System Administrators Manage Software Updates. In Fifteenth Symposium on Usable Privacy and Security (SOUPS","author":"Li Frank","year":"2019","unstructured":"Frank Li, Lisa Rogers, Arunesh Mathur, Nathan Malkin, and Marshini Chetty. 2019. Keepers of the Machines: Examining How System Administrators Manage Software Updates. In Fifteenth Symposium on Usable Privacy and Security (SOUPS 2019). USENIX Association, 273\u2013288."},{"key":"e_1_3_2_1_34_1","volume-title":"Retrieved","author":"A\u00a0Security","year":"2022","unstructured":"RSA\u00a0Security LLC. 2022. Archer GRC Solution. Retrieved February 21, 2022 from https:\/\/www.archerirm.com\/content\/grc"},{"key":"e_1_3_2_1_35_1","volume-title":"Retrieved","author":"Maayan Gilad","year":"2022","unstructured":"Gilad Maayan. 2022. Five years later, Heartbleed vulnerability still unpatched. Retrieved April 24, 2022 from https:\/\/blog.malwarebytes.com\/exploits-and-vulnerabilities\/2019\/09\/everything-you-need-to-know-about-the-heartbleed-vulnerability\/"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1093\/fampra\/13.6.522"},{"key":"e_1_3_2_1_37_1","volume-title":"Retrieved","year":"2022","unstructured":"Marval. 2022. Marval ITSM. Retrieved February 20, 2022 from https:\/\/www.marval.co.uk\/"},{"key":"e_1_3_2_1_38_1","volume-title":"21st USENIX Security Symposium (USENIX Security 12)","author":"Maurer Matthew","year":"2012","unstructured":"Matthew Maurer and David Brumley. 2012. TACHYON: Tandem execution for efficient live patch testing. In 21st USENIX Security Symposium (USENIX Security 12). 617\u2013630."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.17763\/haer.62.3.8323320856251826"},{"key":"e_1_3_2_1_40_1","first-page":"40","article-title":"Creating a patch and vulnerability management program","volume":"800","author":"Mell Peter","year":"2005","unstructured":"Peter Mell, Tiffany Bergeron, David Henning, 2005. Creating a patch and vulnerability management program. NIST Special Publication 800 (2005), 40.","journal-title":"NIST Special Publication"},{"key":"e_1_3_2_1_41_1","volume-title":"Retrieved","year":"2022","unstructured":"Microsoft. 2022. Microsoft System Center Configuration Manager. Retrieved February 16, 2022 from https:\/\/docs.microsoft.com\/en-us\/mem\/configmgr\/"},{"key":"e_1_3_2_1_42_1","volume-title":"Retrieved","year":"2022","unstructured":"Microsoft. 2022. Windows Server Update Services. Retrieved February 17, 2022 from https:\/\/docs.microsoft.com\/en-us\/windows-server\/administration\/windows-server-update-services\/get-started\/windows-server-update-services-wsus"},{"key":"e_1_3_2_1_43_1","volume-title":"Linux Patch Management: With Security Assessment Features. In International Conference on Internet of Things, Big Data and Security. 270\u2013277","author":"Midtrapanon Soranut","year":"2019","unstructured":"Soranut Midtrapanon and Gary\u00a0B Wills. 2019. Linux Patch Management: With Security Assessment Features. In International Conference on Internet of Things, Big Data and Security. 270\u2013277."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.48"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1201\/1086\/43808.12.5.20031101\/78486.2"},{"key":"e_1_3_2_1_46_1","volume-title":"Retrieved","author":"NIST.","year":"2022","unstructured":"NIST. 2022. NVD Common Vulnerability Scoring System. Retrieved March 10, 2022 from https:\/\/nvd.nist.gov\/vuln-metrics\/cvss"},{"key":"e_1_3_2_1_47_1","volume-title":"Investigation: WannaCry cyber attack and the NHS. Report by the Comptroller and Auditor General","author":"National","year":"2017","unstructured":"National\u00a0Audit Office. 2017. Investigation: WannaCry cyber attack and the NHS. Report by the Comptroller and Auditor General. Department of Health."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.22323\/1.133.0031"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/s12083-012-0128-8"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-008-9102-8"},{"key":"e_1_3_2_1_51_1","unstructured":"Thomas\u00a0A. Schwandt. 1997. Qualitative Inquiry. Sage London."},{"key":"e_1_3_2_1_52_1","volume-title":"Retrieved","author":"Security Accenture","year":"2021","unstructured":"Accenture Security. 2021. State of Cybersecurity Resilience 2021. Retrieved March 10, 2022 from https:\/\/www.accenture.com\/_acnmedia\/PDF-165\/Accenture-State-Of-Cybersecurity-2021.pdf"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884833"},{"key":"e_1_3_2_1_54_1","volume-title":"Basics of Qualitative Research : Techniques and Procedures for Developing Grounded Theory","author":"Strauss L.","unstructured":"Anselm\u00a0L. Strauss and Juliet\u00a0M. Corbin. 1998. Basics of Qualitative Research : Techniques and Procedures for Developing Grounded Theory (2nd ed.). Sage.","edition":"2"},{"key":"e_1_3_2_1_55_1","volume-title":"Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory","author":"Strauss L.","unstructured":"Anselm\u00a0L. Strauss and Juliet\u00a0M. Corbin. 2007. Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory (3rd ed.). Sage.","edition":"3"},{"key":"e_1_3_2_1_56_1","volume-title":"Retrieved","year":"2022","unstructured":"Tenable. 2022. Nessus. Retrieved April 21, 2022 from https:\/\/www.tenable.com\/products\/nessus"},{"key":"e_1_3_2_1_57_1","volume-title":"Retrieved","year":"2022","unstructured":"Tenable. 2022. tenable.sc. Retrieved February 17, 2022 from https:\/\/www.tenable.com\/products\/tenable-sc"},{"key":"e_1_3_2_1_58_1","volume-title":"Sixteenth Symposium on Usable Privacy and Security (SOUPS","author":"Tiefenau Christian","year":"2020","unstructured":"Christian Tiefenau, Maximilian H\u00e4ring, Katharina Krombholz, and Emanuel von Zezschwitz. 2020. Security, Availability, and Multiple Information Sources: Exploring Update Behavior of System Administrators. In Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020). USENIX Association, 239\u2013258."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/NTMS.2015.7266506"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678566"},{"key":"e_1_3_2_1_61_1","volume-title":"Retrieved","year":"2022","unstructured":"VMware. 2022. VMware Workspace ONE. Retrieved February 17, 2022 from https:\/\/www.vmware.com\/products\/workspace-one.html"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416590"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920317"}],"event":{"name":"ASE '22: 37th IEEE\/ACM International Conference on Automated Software Engineering","location":"Rochester MI USA","acronym":"ASE '22"},"container-title":["Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3551349.3556969","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3551349.3556969","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T07:55:01Z","timestamp":1755849301000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3551349.3556969"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,10]]},"references-count":63,"alternative-id":["10.1145\/3551349.3556969","10.1145\/3551349"],"URL":"https:\/\/doi.org\/10.1145\/3551349.3556969","relation":{},"subject":[],"published":{"date-parts":[[2022,10,10]]},"assertion":[{"value":"2023-01-05","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}