Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
A changing landscape
Rohyt Belani, 2005-09-07

In 2004, I came across an empirical study published by the CERT/CC that indicated a diminishing correlation between the number of vendor-issued vulnerabilities and the number of reported security incidents. In the years prior to 2002, the number of reported security breaches had always been proportional to the number of vendor-published vulnerabilities. That corollary made sense, since attacks and worms followed vulnerabilities. However, in 2003 and beyond this was no longer the case. The number of incidents rose dramatically as compared to the number of published vulnerabilities.

Comments Mode:
A changing landscape 2005-09-07
Anonymous (1 replies)
Re: A changing landscape 2005-09-07
Anonymous (1 replies)
Re: Re: A changing landscape 2005-09-22
Anonymous
A changing landscape 2005-09-07
Anonymous
A changing landscape 2005-09-08
Anonymous
A changing landscape 2005-09-09
Griggs
A changing landscape 2005-09-09
Augusto P Barros
changing our point of view 2005-09-12
Alexey Vesnin (1 replies)
Yes, end-user's ignorance is not an indulgention. Banks shud, but MUST NOT provide such a links about threats in Internet. Do you know the driving rules when you're going to another country on a car? Yes, you are, because of your safety at first. Is Internet something different? You must know - or at least make some common sense - what's behing a next door you're opening before actually opening it. Or it just can be a bomb. Internet Explorer - actually Internet Exploiter - is not to blame. End-user have it's own mind to deceide which browser to use. RSA SecurID - I'm integrating it inside my employers' network right now at that moment - and it's going good except one thing : they beleive it's too expencive. Until the end-users will be same time so rational for today and so blind for tomorrow - phishers and other hackers will be breathin' on their back. Remember - hack is just a stupidity tax!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/352/32358#32358
Re: changing our point of view 2005-09-15
Anonymous (2 replies)
Re: Re: changing our point of view 2005-09-20
Alexey Vesnin







 

Privacy Statement
Copyright 2008, SecurityFocus