In Depth

Geekonomics Excerpt: The Perversity of Patching

In this excerpt from his new book Geekonomics, David Rice focuses on the security and economic impact of patching commercial software. It’s not a pretty picture.

By David Rice

January 02, 2008CSO

The problem with testing software is that it is unlike testing automobiles, bridges, or any other physical item. Unlike physical structures like bridges, which can be tested in a straight forward manner for maximum load bearing capacity, each instruction within software must be tested individually. This is a tedious and complex process as prone to error as creating the software itself. For example, if a bridge can support 200 tons, then it can be rightly assumed by the design engineer the bridge can support all weight less than 200 tons. If a bridge can support 300 fully loaded trucks and the bridge is covered in two feet of ice, it is safe to say the bridge can support a person riding a bike on a sunny day. In contrast, software must be tested for each and every potential value. A software engineer cannot extrapolate between test cases as a civil engineer would be able to do for a physical structure. If one series of instructions within a software application works correctly (for the sake of argument, it can “support” 10lbs), this says nothing about the ability of a similar series of instructions to handle 8lbs, 7lbs, or even 9.9lbs. In the software engineer’s world, each test is separate and distinct, unrelated to and independent from all other tests. This means for even a moderately complex application, billions upon billions of tests must be conducted.

At most, software companies spend about 35 percent of their production time debugging and correcting errors in their products. [58] Unfortunately, due to the immense complexity of testing software, many software errors—particularly damaging defects—remain latent and do not become apparent until a much later time; that is, not until the software application has become popular. By then, it is too late.

As a case in point, Microsoft’s Internet Explorer has a long history of vulnerabilities, making it the poster child of “what not to do” from a security perspective when designing and building a web browser. In response to this unsatisfactory performance on the part of Microsoft to improve its web browser’s security, multiple news columnists and individuals within the Information Security community in 2004 encouraged computer users to forgo using Internet Explorer and use a free, much more “secure” alternative for a web browser called Firefox.[59] Outside of a few thousand early adopters, however, Firefox was certainly a promising new web browser but hardly what anyone would call a popular browser at the time. The call-to-arms changed that, however, and thousands upon thousands of people started downloading Firefox. As friends told friends, Firefox steadily became increasingly popular and increasingly more exposed. Within months of the call-to-arms, similar vulnerabilities that critics complained about in Internet Explorer were being discovered uncomfortably often in Firefox.[60] Not only were they being discovered, but the vulnerabilities in Firefox were being actively exploited by hackers, thus placing computer users in the same dangerous position they were in with Internet Explorer. What happened?

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WEBCAST
The Surest Path to Effective and Efficient Compliance

VeriSignIn this webcast, we explore why and how — with best practices, practical tips and solutions that work — to ease your compliance challenge.

» View the webcast

Featured Sponsors
Sponsored Links

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

The Case for Business Software Assurance ~ Securing Your Applications

IS/IT Project Mgt. Credentials From Villanova - 100% Online

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Data Protection: Challenges for the Traveling User

Key strategies for C-level executives and security staff

Envision Identity-Based Access Control for the Datacenter

Using Likewise to Comply with PCI Data Security Standard

Think your data is safe? Think again. It's time to Outthink the Threat. Get eBook now

IDC Defines an Identity and Access Management Submarket

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

Configuration Assessment: Choosing the Right Solution

Revolutionizing Endpoint Security with a Single Agent

Envision Identity-Based Access Control for the Datacenter

Rolling the dice with your security? Take the Self-Assessment Test now

Digital Identity Protection and Data Security Get Personal

Solving Online Credit Fraud Using Device Reputation

Diebold: Frost & Sullivan Global Physical Security Systems Integrator of the Year

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage