Companies take too long to patch software flaws, exec says
TechWorld.com - Companies are taking too long to patch critical internal vulnerabilities and are still struggling to protect systems against external attacks.
That's according to Qualys Inc. CTO Gerhard Eschelbeck addressing the Black Hat conference in Las Vegas. He said the typical patching time or "half life" for critical internal vulnerabilities is 62 days, about 22 days more than the 40 he suggested companies should be aiming for.
Eschelbeck also said that the time it took companies to patch against critical external vulnerabilities had improved in the last year from an average of 30 days to today's figure of 21 days, about the level of decrease experts predicted. That still means that many companies are doing worse than this. Exploits for vulnerabilities are also being more rapidly deployed, canceling out some of this gain.
The information was culled from 6.6 million anonymous real-world scans undertaken by the company since January 2002, 70% of which were carried out on Qualys customers, with the remaining being random trials by visitors to its Web site. A total of 2,275 vulnerabilities rated "critical" were detected. "Critical" was defined as vulnerabilities that would allow intruders to take control of systems or would result in information loss.
Not surprisingly given its market dominance, the top 10 critical internal vulnerabilities named in Eschelbeck's presentation all related to Microsoft Corp. software. The equivalent list of critical external vulnerabilities ranged across systems, but again problems with Microsoft products featured prominently.
The list of vulnerabilities has seen a 50% annual turnover rate, he said. "Some vulnerabilities occur again and again. They find new breeding grounds. Like human viruses, they find new victims," said Eschelbeck referring to the way in which the same worms tended to recur.
"Vulnerabilities to Web browsers, data centers, mail servers and other internal systems show up consistently in our top list of the most critical vulnerabilities. In most cases, worms are circulating faster than systems being patched inside the network, and organizations have to be more aggressive about protecting their internal systems."
His advice was to assess which vulnerabilities were the most important. "Organizations don't need to catch every vulnerability. They need to catch those which will affect them the most."
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
Rising salaries boost IT optimism, though not everyone is feeling upbeat. Our survey of 4,000+ IT workers shows who's riding the wave and why. Use our interactive tool and compare your own paycheck. Read more...