Microsoft correctly predicts reliable exploits just 27% of the time
Exploitability index ratings useless, experts argue; Microsoft disagrees
November 3, 2009 04:02 PM ETComputerworld - Microsoft's monthly predictions about whether hackers will create reliable exploit code for its bugs were right only about a quarter of the time in the first half of 2009, the company acknowledged Monday.
"That's not as good as a coin toss," said Andrew Storms, director of security operations at nCircle Network Security. "So what's the point?"
In October 2008, Microsoft added an "Exploitability Index" to the security bulletins it issues each month. The index rates bugs on a scale from 1 to 3, with 1 indicating that consistently-successful exploit code was likely in the next 30 days, and 3 meaning that working exploit code was unlikely during that same period.
The idea was to give customers more information to decide which vulnerabilities should be patched first. Before the introduction of the index, Microsoft only offered impact ratings -- "critical," "important," "moderate" and "low" -- as an aid for users puzzled by which flaws should be fixed immediately and which could be set aside for the moment.
But in the first half of this year, Microsoft correctly predicted exploits just slightly more than one out of every four times.
"Forty-one vulnerabilities were assigned an Exploitability Index rating of 1, meaning that they were considered the most likely to be exploited within 30 days of the associated security bulletin's release," Microsoft stated in its bi-annual security intelligence report, which it published Monday. "Of these, 11 were, in fact, exploited within 30 days."
That means Microsoft got it right about 27% of the time.
Nonetheless, Microsoft stuck up for its exploit predictions. "For the 41 vulnerabilities rated with an Exploitability of '1,' 11 exploits have been discovered and the remaining could be exploited reliably, but those exploits haven't been published publicly," a company spokesman explained in an e-mail response to questions. "The lack of a published exploit doesn't mean the rating itself is inaccurate, as the index assesses what's possible given the latest known exploitation techniques."
Microsoft also tallied its predictions by security bulletins -- in many cases a single bulletin included patches for multiple vulnerabilities -- to come up with a better batting average. "Sixteen bulletins received a severity rating of Critical," it said in its report. "Of these, 11 were assigned an Exploitability Index rating of 1. Five of these 11 bulletins addressed vulnerabilities that were publicly exploited within 30 days, for an aggregate false positive rate of 55%."
The company defended its poor showing -- even on a bulletin-by-bulletin level it accurately predicted exploitability only 45% of the time -- by saying it was playing it safe. "The higher false positive rate for Critical security bulletins can be attributed to the conservative approach used during the assessment process to ensure the highest degree of customer protection for the most severe class of issues," said Microsoft.
exploitability index
Additional Resources



White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

