
GUEST COMMENTARY
The folly of vulnerability seeking
Pete Lindstrom, CISSP 10.11.2004
Rating: -3.70- (out of 5)




|
New vulnerabilities are discovered and disclosed with alarming frequency these days. Like clockwork, 10 vulnerabilities are found each day to augment the leaks in our already-sinking ships. And we welcome the news with masochistic greed. The reality is that these newest vulnerabilities, regardless of individual identity and characteristics, are comfort food for security professionals, giving us work to do that appears useful and yet contributing to an overall weakening of defenses in our computing infrastructure.
There are two primary reasons that security professionals use to justify the practice of vulnerability seeking:
1) It is better to know about a specific vulnerability than not to be aware of it. This argument also has a corollary that every vulnerability found is one less to worry about. The problem here is that we will never find all of the vulnerabilities, and even if we did we couldn't prove it nor would it be prudent to act as if it were true. Given the strong likelihood (if history is our guide) that there are more vulnerabilities being created every day (by developers) than are being discovered, we are taking one step forward and two steps back.
2) It is better that we find the vulnerability before the bad guys do. This gets even more nefarious when someone throws in the notion of state-sponsored espionage, access to source code, etc. Sure, it is an admirable goal to attempt to find these vulnerabilities but the numbers just don't work. With so many vulnerabilities to choose from, how would we know where to focus our efforts? Even if we did have an idea (hint: Microsoft) the bad guys know this as well and can just as easily start focusing
To continue reading for free, register below or login
To read more you must become a member of SearchSecurity.com

in other areas (hint: Cisco or application layer). With no control over the bad guys, we lose every time trying to predict their behavior.
Once evaluated, neither reason provides a good foundation for continuing the practice of vulnerability seeking, but it gets much worse when we consider the consequences:
Ultimately, it is no big accomplishment to find vulnerabilities. Think of the things that could be done to better characterize and contain the threat. Things like identifying the allowed behaviors of complex software to create "Software Safety Data Sheets" in the same vein as Material Safety Data Sheets in the chemical world. Things like deploying and monitoring honeypots to distract attackers and waste their time. Things like developing technical threat models to protect against attacks regardless of whether vulnerability is known or not. Things like infiltrating the command and control of botnets to weaken the attackers.
The days of vulnerability hunting in support of better security are over. We have unsuccessfully "fought the good fight" for years under the lofty banner of trying to make computing environments more secure. But this failure is no surprise, because we were doomed from the start. With today's threats demonstrating an overwhelming level of power and complexity, the amount and extent of damage are too great to continue on with our traditional process of discovery and disclosure.
About the author
Pete Lindstrom, CISSP, is research director at Spire Security.
Have an opinion on this article? E-mail your letters to Shawna McAlearney, and include your name, title and organization. Letters may be edited for space and clarity.
 |

|
Rate this Tip
|
To rate tips, you must be a member of SearchSecurity.com. Register now
to start rating these tips. Log in if you are already a member.
|


');
// -->
DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.
|
 |
|
|
 |
|
 |