Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
A changing landscape
Rohyt Belani, 2005-09-07

In 2004, I came across an empirical study published by the CERT/CC that indicated a diminishing correlation between the number of vendor-issued vulnerabilities and the number of reported security incidents. In the years prior to 2002, the number of reported security breaches had always been proportional to the number of vendor-published vulnerabilities. That corollary made sense, since attacks and worms followed vulnerabilities. However, in 2003 and beyond this was no longer the case. The number of incidents rose dramatically as compared to the number of published vulnerabilities.

Comments Mode:
A changing landscape 2005-09-07
Anonymous (1 replies)
Re: A changing landscape 2005-09-07
Anonymous (1 replies)
Re: Re: A changing landscape 2005-09-22
Anonymous
A changing landscape 2005-09-07
Anonymous
A changing landscape 2005-09-08
Anonymous
A changing landscape 2005-09-09
Griggs
IMO and in this case I think patching and employing good security practices will never be enough. With activities like online banking there's an up side and down side. The up side is convenience while the down side is the risk of having your account breached and looted. One of the best ways to avoid the risk in this area is to conduct banking activities by reverting back to the old fashioned method of driving there.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/352/32350#32350
A changing landscape 2005-09-09
Augusto P Barros
changing our point of view 2005-09-12
Alexey Vesnin (1 replies)
Re: changing our point of view 2005-09-15
Anonymous (2 replies)
Re: Re: changing our point of view 2005-09-20
Alexey Vesnin







 

Privacy Statement
Copyright 2009, SecurityFocus