Information Age: News, analysis & insight for IT & business leaders

 

Security flaws 'never die', concludes study

10 February 2006  

A new Internet security study has concluded that even for the most serious flaws, half of the vulnerable Internet-connected systems remain unpatched a month after the flaw has been uncovered.

31 July 2003 A new Internet security study has concluded that even for the most serious flaws, half of the vulnerable Internet-connected systems remain unpatched a month after the flaw has been uncovered.

Furthermore, many old vulnerabilities do not die out completely, but often make a comeback after a period of time, according to Gerhard Eschelbeck, chief technology officer of security software supplier Qualys.

Eschelbeck was speaking this week at the Black Hat Briefings security conference in Las Vegas, Nevada.

Eschelbeck believes that the main reason why security flaws keep resurfacing is because of the installation and re-installation of old software, typically from CD-Roms that might be found lying around in the IT department.

When the software is installed and the server connected to the network or Internet, IT staff rarely take the time to find out if it needs patching.

Qualys specialises in vulnerability assessment software and services. The company's study is the result of some 1.5 million scans done during the last 18 months.

However, it did find that many companies are prioritising security and patch management according to the perceived seriousness of flaws. While serious flaws would be dealt with almost immediately, they might take as much as two months to deal with less serious flaws.


Comments 

There are currently no comments on this article

People who read this also read...

Platform Computing - Category winner

Since 1992, Platform has established a reputation as an industry leader in High Performance Computing (HPC) management software, bringing the most powerful commercial HPC solutions to leading global enterprises.

Cutting edge intelligence

What trends are defining the business intelligence market of the future?

 
Advertisement

White Papers

Read article

Developing ios Solutions for Business

Whitepapers

Quickly develop and deploy custom iPad and iPhone solutions. With FileMaker Pro, iPad and iPhone solutions can be prototyped and completed in hours or days versus weeks or months. No iOS application programming or design experience is required.

Read article

IDC Spotlight: Access Control and Certification

Whitepapers

Read this brief for best practices on managing user access compliance.

Read article

GPS World

Whitepapers

Is the PREMIER global media brand serving the exploding world of positioning and navigation for OEM, commercial and consumer applications.

More
div class="banner">