Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Security Experts Tighten Grip on Flaws Process

    Written by

    Dennis Fisher
    Published August 4, 2003
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      A proposed voluntary plan for handling vulnerability disclosures is drawing fire from security researchers and other critics, even as new research shows that such a plan is sorely needed to help protect networks.

      The guidelines are the work of the Organization for Internet Safety, a group of security companies and software developers, and define a process for notifying vendors of flaws, disclosing them to the public and dealing with exploit code. The document has been warmly received by many in the security community.

      However, independent researchers who do the lions share of the vulnerability research that the guidelines are meant to cover are less thrilled with the plan. Security researchers at the Black Hat Briefings conference here last week criticized the group for failing to include mechanisms to ensure accountability if vendors fail to follow the plan. OIS members said they purposely eliminated such a section because the plan is voluntary and theres no way to police vendors.

      The laws of flaws

      Results of Qualys vulnerability research

      • The number of vulnerable systems drops by half 30 days after flaw is disclosed
      • Eighty percent of exploits are available within 60 days of disclosure
      • Fifty percent of most prevalent and critical flaws are replaced annually by other flaws
      • Life span of some vulnerabilities is virtually unlimited

      Instead, members said the court of public opinion would ultimately judge members on their compliance.

      “These guidelines dont let us off the hook,” said Scott Culp, senior security strategist at Microsoft Corp., one of the founding members of OIS, of Redmond, Wash. “They actually increase the pressure on us. These guidelines give the finders options if we stall and dont do things right.”

      But some still didnt buy it. “In short, the OIS guidelines will not be adopted by the community at large. It is a process and set of guidelines made by and for the software vendors, with a minimal level of engagement from a select few security companies sharing vested interests,” said Thor Larholm, senior security researcher at PivX Solutions LLC, a security consultancy based in Newport Beach, Calif. “The OIS guidelines are not a practical solution to vulnerability disclosure but a political tool that enables the software vendors to point fingers at researchers that do not choose to play by their rules.”

      Some OIS members conceded the plan isnt perfect and that abuse is possible. “Theres a chance the vendors will not do the right thing,” said Chris Wysopal, director of research and development at @Stake Inc., based in Cambridge, Mass.

      The “Security Vulnerability Reporting and Response Process” lays out a regimented timeline and set of steps for the interaction between the person who discovers a vulnerability and the vendor or vendors affected by the problem. It addresses how and when to notify the vendor, how the vendor should respond, how long the researcher should wait for a response, and how to resolve disputes.

      Meanwhile, new research shows that for vulnerabilities identified as critical, the number of vulnerable systems drops by 50 percent every 30 days, according to data assembled as part of an ongoing research effort by Gerhard Eschelbeck, chief technology officer of Qualys Inc., in Redwood Shores, Calif. This so-called half-life of a vulnerability doubles with each progressively lower degree of severity. In fact, Eschelbeck found that some flaws have a virtually unlimited life span.

      Security experts said the research project was important in that it shows some education is still needed regarding the importance of patching, making it all the more critical that vulnerabilities are not disclosed before patches are available.

      “[Researchers] have to understand that its not a three-day proposition to do a really good job on a patch,” said Mary Ann Davidson, chief security officer at Oracle Corp., also based in Redwood Shores. “Its a fine line. But if these guys work with us responsibly, we can all protect the customers. Some of them just want to tell their friends as soon as they find something.”

      Some members of OIS showed a little frustration with the criticisms coming from the security researchers about the lack of penalties for vendors that fail to follow the new process.

      “The stick of full disclosure has worked, and I think its time that some of the researchers cut them some slack and recognize that,” said Scott Blake, vice president of information security at BindView Corp., based in Houston, and one of the founding members of OIS.

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×