In Depth
Patching Software: The Big Fix
Insecure software is forcing vendors to do what they've never done before: make good software
By Scott Berinato
In addition, a bevy of new research was published that proves there is an ROI for vendors and users in building more secure code. Plus, a new class of software tools was developed to automatically ferret out the most gratuitous software flaws.
Put it all together, and you get
Mary Ann Davidson, CSO at Oracle, claims that now "no one is asking for features; they want information assurance. They're asking us how we secure our code." Adds Scott Charney, chief security strategist at Microsoft, "Suddenly, executives are saying, We're no longer just generically concerned about security."
So What Are We Doing About It?
Specifically, all this concern has led to the empowerment of everyone who uses software, and now they're pushing for some real application security. Here are the reasons why.
Vendors have no excuse for not fixing their software because it's not technically difficult to do. For anyone who bothers to look, the numbers are overwhelming: 90 percent of hackers tend to target known flaws in software. And 95 percent of those attacks, according to SEI's Cross, among others experts, exploit one of only seven types of flaws. (See "Common Vulnerabilities," opposite page.) So if you can take care of the most common types of flaws in a piece of software, you can stop the lion's share of those attacks. In fact, if you eliminate the most common security hole of all
"It frustrates me," says Cross. "It was kind of chilling when we realized half-a-dozen vulnerabilities were causing most of the problems. And it's not complex stuff either. You can teach any freshman compsci student to do it. If the public understood that, there would be an outcry."
SEI and others such as @Stake are shining a light on these startling facts (and making money in doing so). It has started to have an effect. Wysopal at @Stake says he's seeing more empowered and proactive customers, and in turn, vendors are desperately seeking ways to keep those empowered customers.
patching
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



