Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

12:00 PM
Connect Directly

The 'Remediation Gap:' A 4-Month Invitation To Attack

Organizations set out the welcome mat for cyberattackers by taking an average of 120 days to patch flaws.

As impactful as targeted attacks can be on organizations when they hit the mark, non-targeted and automated attacks that focus on known vulnerabilities still pose a significant threat to the enterprise. According to a new study out today by Kenna security, the volume of vulnerabilities exploited by untargeted attacks only continues to snowball while organizations continue to fall down in remediating these known vulnerabilities.

“The public has grown plenty familiar with hackers seeking out a specialized target, such as Ashley Madison. But automated, non-targeted attacks still remain the most significant threat to businesses of all sizes,” said Karim Toubba, CEO of Kenna.

Kenna took a deep dive into vulnerability and exploit data from 50,000 organizations over the course of a nearly two-year period from January 2014 to September 2015. It looked at 250 million vulnerabilities and over a billion breach events at these companies and confirmed something most security pros have been warning about for years: organizations taking way too long to remediate their vulnerabilities. The firm found that it takes an average of between 100 to 120 days to patch a flaw once it's found. Meanwhile, the probability of a vulnerability being exploited rises to 90 percent by the time the flaw has been known for between 40 to 60 days.

It's no surprise, then, that the volume of exploits has exploded in 2015. Kenna found that successful exploits rose over four-fold this year. The firm witnessed more than 1.2 billion successful exploits in 2015, compared to just 220 million successful exploits in 2013 and 2014 combined.

In many cases the most successful automated campaigns home in on vulnerabilities left open for far longer than the average 120 day remediation window.

"When we talk about unremediated vulnerabilities that fall prey to attacks at scale, one of the points we need to make is that the vulnerabilities in question are often very old, well-known weaknesses that simply haven’t been fixed yet," the report said. "We’ve seen this over and over again as we evaluate the data."

For example, the report detailed how the positively ancient Slammer vulnerability in SQL Server 2000 still provides fodder for automated attacks. In 2014 Kenna found evidence that it was successfully exploited 156,000 times.

"It’s not new, it’s not hip, it’s not current, so one talks about it – but it’s a significant threat," the report said.

That's, of course, the very long tail of exploitation. More recent, but still well-known vulnerabilities like Heartbleed are proving even more useful to attackers. Based on its data, Kenna predicts that over the next month there will be 5000 successful exploitations of Heartbleed per day

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
10/1/2015 | 7:49:01 AM
Re: home/hone
You have the eyes of a copy editor. Glad you are paying attention!
User Rank: Apprentice
9/30/2015 | 4:16:54 PM
I'd just like to praise you for using "home" instead of the, incorrect, "hone." Nit-picky? Yes, but it's like a little mosquito bite for us OCD types.
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC,  12/5/2019
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2019-12-10
JBoss KeyCloak: XSS in login-status-iframe.html
PUBLISHED: 2019-12-10
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
PUBLISHED: 2019-12-10
openstack-utils openstack-db has insecure password creation
PUBLISHED: 2019-12-10
rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection
PUBLISHED: 2019-12-10
marc-q libwav through 2017-04-20 has a NULL pointer dereference in wav_content_read() at libwav.c.