Powered by InformationWeek Business Technology Network
Topics:
Security
Zero-Day Attacks Trend Down? I Don't Give A Flying Hoot
In a story on our sister site, Dark Reading, Kelly Jackson Higgins notes that attackers are increasingly employing known bugs, at the expense of zero-day exploits. I don't care. And I don't think you should, either. From the story, quoting Kris Lamb, operations manager of X-Force Research and Development for IBM Internet Security Systems:
The takeaway from that trend is this: not enough people are patching. If more people patched, the attackers would be forced to find and use zero-days. That would raise their cost of doing business. And that would be a good thing. But the important thing to note is that you already have to assume that any networked computer is constantly under assault. And the fact is that if it's attached to the Internet: it is. And you need to assume that your custom-developed and over-the-shelf software is littered with security holes. It probably is. That's why you should ignore all of the zero-day exploit talk. Because you have to secure your systems as if you already have zero-day vulnerabilities and that the attackers already know about them. I'll say this again: You have to secure your systems as if you're always under assault from zero-day attacks. Because too many days of the year, this condition is probably true. And that's why zero-day talk is nothing but hot air. Patch the known flaws. Monitor your traffic for anomalies. Protect yourself as if you are always under assault. And call it a day. And if you want to focus extra attention somewhere, direct your attention to hardening your end point applications, and your Web applications. That's where the action is. « Full Nelson: Mobile + Search + Taptu | Main | Dell Buys Brother's Company MessageOne For $155 Million » |
| Sign Up Now For InformationWeek News Alerts |