Computer Vulnerability-to-Worm Cycle Compressing Dramatically

Printer-friendlyE-mail this news to a friendYour comment

Foundstone Inc., expert in strategic security, published an analysis of computer worm history revealing a potentially dangerous trend. The vulnerability-to-worm cycle has compressed from 288 days in 1999 to just 10 days in 2004, putting organizations and consumers at higher risk for attack.

Foundstone's analysis centers on high profile worms released between 1999 and 2004, including: Melissa, Sadmind, Sonic, Bugbear, Code Red, Nimda, Spida, MS SQL Slammer, Slapper, Blaster, Witty and Sasser. Worms that took advantage of user interaction (e.g. executing attachments) and remotely controlled "bots" were reviewed, but not included in the trend report in order to focus on completely automated threats.

"This trend is alarming as it demonstrates what we have sensed for years, that the cycle from vulnerability to worm is shortening dramatically -- putting increasing pressure on IT departments to remediate vulnerabilities faster than ever," said Stuart McClure, president and chief technology officer for Foundstone and author of the worm research. "The window within which the good guys have to work is closing fast."

"IT security is a chess game in which cyberattackers have the white pieces and thus move first," commented John Pescatore, analyst for Gartner. "Organizations can control the middle of the chessboard by implementing vulnerability management and intrusion prevention approaches to prevent and respond quickly to attacks."

"In today's world, it's nearly impossible to protect your enterprise's digital assets without a vulnerability management system," said Dave Cole, vice president of product management for Foundstone. "Foundstone Enterprise customers benefit from early warning of breaking threats, enabling a timely, effective response for even today's rapid turn-around worms. In addition, if the security of a customer is ever compromised for any reason, Foundstone Enterprise gives them the ability to quickly assess which machines on the network have been affected."

Foundstone's Enterprise Risk Solutions(TM) software helps organizations comprehensively discover, inventory, prioritize, and remediate all assets on a global network. The suite provides exceptionally accurate, high-speed vulnerability assessment of all network assets, intuitive reports and metrics, and a tightly integrated threat correlation module which correlates critical threats with prioritized assets so security and network operations can focus on the assets that matter the most.

19.05.2004, Foundstone(R) Inc.




Comments on this news 


Write your comment on this news

Subscribe to the newsletter

Never miss a story and stay informed with our newsletter.
Your email:  
RSS-Feed: All current newsOur News on your website

More current news

VASCO gives an answer to security concerns when deploying Software as a Service (SaaS)
Making penetration testing work
Double trouble, as new Facebook worm targets Google Reader
Wipro and Fortify Software Form Partnership to Assure the Security of Client Software Worldwide
VASCO launches PKI-based authentication solution

News on other topics

SharePartXXL has released Version 2.0 of the Taxonomy Extension for WSS/MOSS
RTL, VOX and SUPER RTL operate communication portals with CONTENS
Finally: A professional Open Source Digital Asset Management (DAM)
Pentland selects FirstSpirit for global web content management
ContentServ has successfully extended its International Partner Network in 2008

Erotik Fotografen
The Content Management PortalThe Document Management PortalThe IT Security PortalThe Customer Relationship Management PortalThe E-Commerce PortalThe Enterprise Resource Planning PortalPortal on VoIP and mobile communication The directory of Clinic IT SolutionsThe directory for IT professionals
homeimprintprivacy policycontactadvertising

know how

news

events

security alerts

Quick search