Advertisement
Promo

Security threats Toolkit

Prioritising patches will help keep bad guys at bay

Joris Evers CNET News

Published: 15 Nov 2005 18:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

System administrators may be dealing with security vulnerabilities more quickly, but the bad guys are still leading the race.

That's because threats that exploit the flaws are also appearing sooner, according to research presented on Tuesday.

Although patching practices improved in the last year, nearly 70 percent of systems are currently vulnerable and at risk of attack, Gerhard Eschelbeck, chief technology officer and vice-president of engineering at vulnerability management vendor Qualys, said during a presentation at the Computer Security Institute conference in Washington.

In 2005, administrators have shaved two days off the "vulnerability half life," the time it takes to reduce the number of vulnerable systems that have direct Internet connections, Eschelbeck said.

Every 19 days, half of all the critical vulnerabilities are currently dealt with, either via a patch, a workaround or another security solution, according to Eschelbeck. That compares with 21 days a year ago and 30 days two years ago, he said.

But 19 days to fix half of all the vulnerable systems is not good enough. "Eighty percent of the exploits come out within the first half life of the vulnerability," Eschelbeck said. The "window of exposure" continues to shrink.

Administrators take their time to patch internal systems, which are behind a firewall or protected by other security technologies. Half of the vulnerable systems are now protected in 48 days, compared to 62 days last year, Eschelbeck said.

To better secure their systems, Eschelbeck recommends that organisations prioritise their patches. "Ninety percent of exposure is caused by 10 percent of the vulnerabilities," he said. To assist in the prioritisation task, Eschelbeck pitched the CVSS, which was introduced earlier this year.

"With the constant evolution and complexity of critical vulnerabilities, it is impossible for an organisation to fix every potential flaw. It is essential to prioritise and patch those vulnerabilities that are most damaging to their individual network," he said.

For his research, Eschelbeck analysed data from more than 32 million vulnerability scans. For 2003 and 2004, the data is for the full year, while the data for 2005 is for the first three quarters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
53 out of 120 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters