OT: Software Vulnerability Overview 2005

  • Thread starter Thread starter Azzman
  • Start date Start date
Azzman said:
This bulletin provides a year-end summary of software vulnerabilities
that were identified between January 2005 and December 2005.

http://www.us-cert.gov/cas/bulletins/SB2005.html

And it makes for fascinating reading <grin>. Keep in mind that there've
been a lot of articles spun off this report *and* there are a number of
problems with the report's methodology, ergo, news-consumers beware.
Below is a sample of the problems w/the report by Security Focus author,
Rob Lemos...
Four databases were surveyed: The Computer Emergency Response Team
(CERT) Coordination Center's database, the National Vulnerability
Database (NVD), the Open-Source Vulnerability Database (OSVDB), and
the Symantec Vulnerability Database. (SecurityFocus is owned by
Symantec.)

The number of flaws cataloged by each database in 2005 varied widely,
because of differing definitions of what constitutes a vulnerability
and differing editorial policy. The OSVDB - which counted the highest
number of flaws in 2005 at 7,187 - breaks down vulnerabilities into
their component parts, so what another database might classify as one
flaw might be assigned multiple entries. SecurityFocus had the lowest
count of the vulnerabilities at 3,766.

The variations in editorial policy and lack of cross-referencing
between databases as well as unmeasurable biases in the research
community and disclosure policy mean that the databases - or refined
vulnerability information (RVI) sources - do not produce statistics
that can be meaningfully compared, Steve Christey, the editor of the
Common Vulnerability and Exposures (CVE), wrote in an e-mail to
security mailing lists on Thursday. The CVE is a dictionary of
security issues compiled by The MITRE Corp., a government contractor
and nonprofit organization.


source:
http://www.theregister.co.uk/2006/01/09/computer_security_flaws_on_the_rise/
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top