Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

2/13/2008
07:47 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Zero-Day Attacks Trend Down? I Don't Give A Flying Hoot

Security researchers and the press like to parse vulnerability trends. They like to argue (among themselves) as to whether zero-day attacks are on the rise, and if the underground is selling or sandbagging the security flaws these black hats uncover. I say: So what? None of this should matter to you.

Security researchers and the press like to parse vulnerability trends. They like to argue (among themselves) as to whether zero-day attacks are on the rise, and if the underground is selling or sandbagging the security flaws these black hats uncover. I say: So what? None of this should matter to you.In a story on our sister site, Dark Reading, Kelly Jackson Higgins notes that attackers are increasingly employing known bugs, at the expense of zero-day exploits.

I don't care. And I don't think you should, either.

From the story, quoting Kris Lamb, operations manager of X-Force Research and Development for IBM Internet Security Systems:

It's not that the bad guys never use zero-days. "But it's how they can use a bunch of exploits to get the most coverage [and success]," Lamb says. "It's less about spending resources on [finding] that zero-day."

He's talking about how attackers are finding it more productive to use known exploits, and that it doesn't pay for them to have to dig through software to find yet-to-be uncovered flaws to exploit for attack.

The takeaway from that trend is this: not enough people are patching. If more people patched, the attackers would be forced to find and use zero-days. That would raise their cost of doing business. And that would be a good thing.

But the important thing to note is that you already have to assume that any networked computer is constantly under assault. And the fact is that if it's attached to the Internet: it is.

And you need to assume that your custom-developed and over-the-shelf software is littered with security holes. It probably is.

That's why you should ignore all of the zero-day exploit talk. Because you have to secure your systems as if you already have zero-day vulnerabilities and that the attackers already know about them.

I'll say this again: You have to secure your systems as if you're always under assault from zero-day attacks.

Because too many days of the year, this condition is probably true.

And that's why zero-day talk is nothing but hot air.

Patch the known flaws. Monitor your traffic for anomalies. Protect yourself as if you are always under assault. And call it a day. So ignore all of the blather about what constitutes a zero-day, or if publically disclosed vulnerabilities slipped 5.4% year over year. Who cares?

And if you want to focus extra attention somewhere, direct your attention to hardening your end point applications, and your Web applications. That's where the action is.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
Breaches Are Inevitable, So Embrace the Chaos
Ariel Zeitlin, Chief Technology Officer & Co-Founder, Guardicore,  11/13/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19010
PUBLISHED: 2019-11-16
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
CVE-2019-16761
PUBLISHED: 2019-11-15
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the [email protected] npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. All versions >1.0...
CVE-2019-16762
PUBLISHED: 2019-11-15
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slpjs npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. Affected users can upgrade to any...
CVE-2019-13581
PUBLISHED: 2019-11-15
An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A heap-based buffer overflow allows remote attackers to cause a denial of service or execute arbitrary ...
CVE-2019-13582
PUBLISHED: 2019-11-15
An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A stack overflow could lead to denial of service or arbitrary code execution.