Advertisement
Promo

Security threats Toolkit

Prioritising patches will help keep bad guys at bay

Joris Evers CNET News

Published: 15 Nov 2005 18:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

System administrators may be dealing with security vulnerabilities more quickly, but the bad guys are still leading the race.

That's because threats that exploit the flaws are also appearing sooner, according to research presented on Tuesday.

Although patching practices improved in the last year, nearly 70 percent of systems are currently vulnerable and at risk of attack, Gerhard Eschelbeck, chief technology officer and vice-president of engineering at vulnerability management vendor Qualys, said during a presentation at the Computer Security Institute conference in Washington.

In 2005, administrators have shaved two days off the "vulnerability half life," the time it takes to reduce the number of vulnerable systems that have direct Internet connections, Eschelbeck said.

Every 19 days, half of all the critical vulnerabilities are currently dealt with, either via a patch, a workaround or another security solution, according to Eschelbeck. That compares with 21 days a year ago and 30 days two years ago, he said.

But 19 days to fix half of all the vulnerable systems is not good enough. "Eighty percent of the exploits come out within the first half life of the vulnerability," Eschelbeck said. The "window of exposure" continues to shrink.

Administrators take their time to patch internal systems, which are behind a firewall or protected by other security technologies. Half of the vulnerable systems are now protected in 48 days, compared to 62 days last year, Eschelbeck said.

To better secure their systems, Eschelbeck recommends that organisations prioritise their patches. "Ninety percent of exposure is caused by 10 percent of the vulnerabilities," he said. To assist in the prioritisation task, Eschelbeck pitched the CVSS, which was introduced earlier this year.

"With the constant evolution and complexity of critical vulnerabilities, it is impossible for an organisation to fix every potential flaw. It is essential to prioritise and patch those vulnerabilities that are most damaging to their individual network," he said.

For his research, Eschelbeck analysed data from more than 32 million vulnerability scans. For 2003 and 2004, the data is for the full year, while the data for 2005 is for the first three quarters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
53 out of 120 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters