When should a security patch be released?

A chart with release timing on the horizontal axis and loss on the vertical axis. A thin rising line shows the loss from attacks growing the longer the release is delayed, a thin falling line shows the loss from too little testing when released too early, and their sum forms a U-shaped total loss curve whose lowest point marks the best timing.

Once a vulnerability is found, deciding when to publish the patch is genuinely hard. Rush and the patch ships without adequate verification; delay and the exposure window grows.

This work represents the vulnerability discovery process as a non-homogeneous Poisson process, because discoveries do not arrive at a constant rate — they cluster shortly after release and change over time.

On that basis it defines a total cost combining the loss from attacks with the cost of developing and verifying the patch, and derives the release timing that minimises it.

The result shows mathematically that earlier is not always better. It provides a basis for deciding security response by calculation rather than by instinct.

Source paper

Optimal security patch release timing under non-homogeneous vulnerability-discovery processes

ISSRE (International Symposium on Software Reliability Engineering) (2009)