On UrbanBaby: Do modern parents try too hard?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Jul 29, 2004 11:47:00 PM

LAS VEGAS--Driven by fast-appearing threats, network administrators are fixing the most prevalent flaws more quickly, according to a new survey.

The survey, released Wednesday by vulnerability assessment firm Qualys at the Black Hat Security Briefings here, found that the average half-life of a vulnerability--the length of time it takes for half of assailable computers to be fixed--has fallen to 21 days this year from 30 days in 2003.

However, the report found improvements only with systems connected directly to the Internet. Administrators took longer to patch computers located within a local area network, believing they were safe. Companies are typically patching flaws in internal systems within 62 days this year; Qualys did not measure the time it took to patch internally in 2003.

"If you look at the challenge that companies have internally, it is a factor of 10 more complicated," said Gerhard Eschelbeck, chief technology officer at Qualys.

The numbers are the best-case scenario for how quickly companies patch their systems. Qualys only collects anonymous data from its clients. Because those clients use Qualys' flaw-finding service, they are generally safer than companies not concerned with security--the average company connected to the Internet is likely to patch flaws much slower, Qualys said.

The slow rate at which companies update their systems has caused software makers such as Microsoft to look for better ways to secure customers that have not patched. Those companies need to start fixing their systems, Eschelbeck said.

"Knowing where your problems are is the first step, and then figuring out how critical each problem is is the next," he said.

Moreover, if the average time that companies stay connected to the Internet shrinks, the window of time that worm writers can exploit vulnerabilities to spread their programs is lowered as well.

"We will see those worms hitting in the first two half-lives," Eschelbeck said. "So the first two half-lives are the most important times, because they act as a breeding ground."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 9 Talkback(s)
Linux HA!
Linux is not free support NOT! Drivers hmmm well none for the newest hardware. You need to get it straight Linux cost more for IT too, so sell Linux somewhere else. Home users (average folk) don't get Linux and I won't install it on their PCs Case closed period... (Read the rest)
Posted by: Krazyken39 Posted on: 11/03/05 You are currently: a Guest | | Terms of Use
Ha ha!  php_developer | 07/29/04
ROFL  Loverock Davidson | 07/29/04
Linux patches are ALL over the place  Enterprise. Analyst | 07/29/04
Windows patches are ALL over the place  Cardinal_Bill | 07/29/04
Linux HA!  Krazyken39 | 11/03/05
Let's take care of people who are too stupid to take care of themselves.  GhostInTheSystem | 07/30/04
Too Stupid.  boomslang_z | 07/31/04
BSOD patching  crocd | 08/04/04
Linux patching  crocd | 08/04/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here