Clemens Sauerwein

Comprehensive Evaluation of patching behavior of major software vendors

After a vulnerability of a software product is public disclosed it takes some time until a patch is available. Ideally a patch is avalaibale at the same time as a vulnerability is disclosed. Since research and practice lack an understanding how long the time span between disclosure and availability of a patch lasts an empirical investigation is needed. The goal of this thesis is to analyze the timespan of public disclosure until patch availability.

Scope and Tasks

