Advertisement
Promo

Security threats Toolkit

Government tries to secure UK from electronic attack

Munir Kotadia ZDNet.co.uk

Published: 27 Jul 2004 17:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Home Office has said it will start giving advance warning about upcoming security patches and software vulnerabilities to essential public services, such as transportation, health and telecommunications.

The National Infrastructure Security Co-ordination Centre (NISCC), which is part of the Home Office, was set up in 1999 to work with both public and private sector organisations to try and ensure the Critical National Infrastructure can withstand an "electronic" attack.

The majority of viruses and worms are developed by hackers who reverse-engineer patches produced by software developers in order to plug security vulnerabilities.

Over the past few years, the time between a vulnerability being announced -- which is usually the same time that the software patch is issued -- and an exploit being distributed, is shrinking. This means that administrators have less time to secure their systems than ever before.

Security risk management firm TruSecure welcomes the NISCC's idea but warns that sometimes too much information can be more damaging than not enough information.

Malcolm Skinner, director of marketing at TruSecure, said that there are too many vulnerabilities, so if the "essential services" tried responding to them all, they would run into problems.

"There are far too many vulnerabilities out there. What organisations really want to know about are the vulnerabilities that are important and can be exploited," said Skinner.

According to Skinner, simply being informed of vulnerabilities is less important than knowing how to minimise the risk of being infected by an exploit.

"The same things that were said after the first MyDoom are being said now. How many times do we have to say it? If the warning is just to let the services know there is another vulnerability coming out, it's not much use," said Skinner.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
103 out of 224 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters