Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    The Wall of Fear

    Written by

    Dennis Fisher
    Published August 11, 2003
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The numbers are staggering: 4,129 in 2002, up from 2,437 in 2001. And in the first quarter alone this year, there have been 1,993 new vulnerabilities found. The volume of flaws found has been rising at an alarming rate for as long as people have kept statistics.

      As the crushing pace of software development marches on and each successive generation of developers continues to make the same mistakes as its predecessors, the details of the vulnerabilities all begin to run together.

      “Wasnt there a big problem found in IIS [Internet Information Services] recently?”

      “Yeah. Sounded really bad, too, I think. No, wait. It was IOS [Internetwork Operating System].”

      “Have we patched that one?”

      “Not sure. Let me take a look.”

      The constant drumbeat of critical-this-is-huge-patch-it-now-or-be-owned bulletins and the subsequent warnings about exploits being developed and used have combined to form a kind of low hum in the background to which many administrators and IT managers have become immune. This is not a good thing, to say the least.

      The recent widespread vulnerabilities in Cisco Systems Inc.s IOS and Microsoft Corp.s RPC (Remote Procedure Call) service in Windows have again sharpened the focus on this problem. Cisco, of San Jose, Calif., took the extraordinary step of warning its largest customers—backbone providers and large Tier 1 ISPs—about the IOS vulnerability before the problem was publicly disclosed. This drew some criticism but seems to have had the desired effect of preventing any large-scale attack on the core of the Internet.

      By contrast, the Windows RPC flaw was disclosed publicly in mid-July and was accompanied by dire warnings of imminent attacks against the weakness, which is found in every current version of the operating system. Microsoft, of Redmond, Wash., strongly encouraged its customers to apply the patch, as it always does. But within two weeks, several sophisticated attack tools were being distributed within the security underground, and monitoring companies reported seeing regular coordinated attacks against vulnerable machines.

      “The elevated media attention on the potential ramifications of not installing this new patch raises the perceived importance of patch management from a network administration process to a crucial business management issue,” said Gary Stowell, vice president of product management and business development at St. Bernard Software Inc., of San Diego. “Companies can no longer afford to take a laissez-faire approach to patching their corporate networks and securing their informational assets.”

      At a panel discussion on vulnerability handling during the recent Black Hat Briefings in Las Vegas, one of the main lines of questioning was what could be done to encourage, if not coerce, enterprises to patch their systems. Panelists were all part of the Organization for Internet Safety and had a hand in the development of that groups policy on vulnerability handling.

      Although the panelists said patching was outside the scope of their current work, they said it might be something theyll look at in the future.

      “We know that patching is an issue. And we may have to take a look at that sometime down the road. Theres definitely some room for someone to help there,” said Rajiv Sinha, manager of security compliance at Oracle Corp., in Redwood Shores, Calif.

      But even if OIS or a similar group eventually develops guidelines for patch management, that would just reinforce what IT staffs already know: Its important to patch your systems. The real problem is finding a way to break through the noise and come up with a system that succeeds in getting people to apply patches.

      Its clear that scare tactics and prophecies of doom are no longer doing the trick. But even the relatively new crop of automated patch deployment solutions leaves some IT managers wanting.

      “People have been burned by patches that break other services, and so they want to do a lot of testing,” said Scott Blake, vice president of information security at BindView Corp., in Houston. “And if something looks like its going to cause problems, they dont use it. Thats the problem.”

      (Editors note: This story has been modified since its original posting to correct a numerical error.)

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×