Commentary
Zero-Day Attacks Trend Down? I Don't Give A Flying Hoot
Security researchers and the press like to parse vulnerability trends. They like to argue (among themselves) as to whether zero-day attacks are on the rise, and if the underground is selling or sandbagging the security flaws these black hats uncover. I say: So what? None of this should matter to you.Security researchers and the press like to parse vulnerability trends. They like to argue (among themselves) as to whether zero-day attacks are on the rise, and if the underground is selling or sandbagging the security flaws these black hats uncover. I say: So what? None of this should matter to you.In a story on our sister site, Dark Reading, Kelly Jackson Higgins notes that attackers are increasingly employing known bugs, at the expense of zero-day exploits.
I don't care. And I don't think you should, either.
More Security Insights
White Papers
- The BlackBerry PlayBook tablet's Good Bones - by BlackBerry
- New Visual and Wizard-Driven Paradigms for Exploring Data and Developing Analytic Workflows
Reports
More >>Webcasts
- Outsourcing Security: What Every Potential Cloud Security Customer Should Know
- Maximize ROI with Database Consolidation onto Private Clouds
From the story, quoting Kris Lamb, operations manager of X-Force Research and Development for IBM Internet Security Systems:
It's not that the bad guys never use zero-days. "But it's how they can use a bunch of exploits to get the most coverage [and success]," Lamb says. "It's less about spending resources on [finding] that zero-day."
He's talking about how attackers are finding it more productive to use known exploits, and that it doesn't pay for them to have to dig through software to find yet-to-be uncovered flaws to exploit for attack.
The takeaway from that trend is this: not enough people are patching. If more people patched, the attackers would be forced to find and use zero-days. That would raise their cost of doing business. And that would be a good thing.
But the important thing to note is that you already have to assume that any networked computer is constantly under assault. And the fact is that if it's attached to the Internet: it is.
And you need to assume that your custom-developed and over-the-shelf software is littered with security holes. It probably is.
That's why you should ignore all of the zero-day exploit talk. Because you have to secure your systems as if you already have zero-day vulnerabilities and that the attackers already know about them.
I'll say this again: You have to secure your systems as if you're always under assault from zero-day attacks.
Because too many days of the year, this condition is probably true.
And that's why zero-day talk is nothing but hot air.
Patch the known flaws. Monitor your traffic for anomalies. Protect yourself as if you are always under assault. And call it a day. So ignore all of the blather about what constitutes a zero-day, or if publically disclosed vulnerabilities slipped 5.4% year over year. Who cares?
And if you want to focus extra attention somewhere, direct your attention to hardening your end point applications, and your Web applications. That's where the action is.
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. | |
|
|
T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting! |
Subscribe to RSSResource Links
This Week's Issue
Technology Whitepapers
- Mobile BI: Actionable Intelligence for the Agile Enterprise
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
- The BlackBerry PlayBook tablet's Good Bones - by BlackBerry
- New Visual and Wizard-Driven Paradigms for Exploring Data and Developing Analytic Workflows
Featured Resource
This is your portal to all the news, product information, technical data, and other information related to the topic of computer user authentication and certification. Visit us to find out how to ensure that computer users are who they say they are.
Learn More












