Tamara Bondar (Carleton University), Hala Assal (Carleton University)

System administrators are the ones primarily responsible for ensuring the security of their systems and services. While security is typically atop their considerations, they also tend to various competing priorities. Through an interview study with 7 sysadmins, and a large-scale survey study with 124 sysadmins in North America, this paper explores factors influencing system administrators’ security vulnerability remediation decisions. In addition, we explore how the vulnerability creator (whether the sysadmin themself or another sysadmin) affects remediation decisions.

Our findings reveal that remediation decisions are often complex and influenced by various factors, including vulnerability severity and the sysadmin’s skills and experience. The creator of the vulnerability had minimal effect on vulnerability remediation decisions, as we found that sysadmins typically assume psychological ownership and moral responsibility towards their systems. Collaboration between sysadmins, and with third-party vendors was recommended by our participants to facilitate vulnerability remediation.

View More Papers

User Comprehension and Comfort with Eye-Tracking and Hand-Tracking Permissions...

Kaiming Cheng (University of Washington), Mattea Sim (Indiana University), Tadayoshi Kohno (University of Washington), Franziska Roesner (University of Washington)

Read More

From Underground to Mainstream Marketplaces: Measuring AI-Enabled NSFW Deepfakes...

Mohamed Moustafa Dawoud (University of California, Santa Cruz), Alejandro Cuevas (Princeton University), Ram Sundara Raman (University of California, Santa Cruz)

Read More

Investigating User Behaviour Towards Fake News on Social Media...

Yasmeen Abdrabou (University of the Bundeswehr Munich), Elisaveta Karypidou (LMU Munich), Florian Alt (University of the Bundeswehr Munich), Mariam Hassib (University of the Bundeswehr Munich)

Read More

Adopt a PET! An Exploration of PETs, Policy, and...

Masoumeh Shafieinejad (Vector Institute), Xi He (Vector Institute and Univesity of Waterloo), Bailey Kacsmar (Amii & University of Alberta)

Read More