_
28-Aug-2008 | 23:11:51

News:

.


Vulnerability Ecosystem
Bookmark Page
Bookmark on digg Bookmark on deli.cio.us Bookmark on reddit Bookmark on Technorati Bookmark on stumbleupon Bookmark on Google Bookmark on Yahoo MyWeb

Vulnerability Ecosystem

From Discovery to Fix

It is an accepted fact that most software written suffers from design and implementation weaknesses. Vulnerabilities are of significant interest when the program containing them is networked or has access to the Internet. Users are exposed to risk when vulnerabilities are discovered, disclosed, and exploited. Software vendors try to match the ever increasing rate of newly discovered security vulnerabilities by providing a fix to have the software patched. Unfortunately, vendors cannot make security fixes available instantly after the discovery of new vulnerabilities or exploits. When a new patch is developed and released by the vendor, users of the software cannot implement it with zero delay. Vulnerability Lifecycle Events

Vulnerability Ecosystem

The many processes from discovery of a new vulnerability to the implementation of a vendor fix build the Vulnerability Ecosystem.

Vulnerability creation

Discovery

Exploitation

Public disclosure

Patch development

Patch implementation