_
28-Aug-2008 | 22:48:33

News:

.



Bookmark Page
Bookmark on digg Bookmark on deli.cio.us Bookmark on reddit Bookmark on Technorati Bookmark on stumbleupon Bookmark on Google Bookmark on Yahoo MyWeb

The Lifecycle of a Vulnerability

Livecycle Events

Distinctive points in time divide the lifecycle of a vulnerability in phases each reflecting a certain state and an associate risk. To capture these states, we devise the following four points in time: the vulnerability Discovery-, Disclosure-, Exploit Availability-, and Patch Availability time. These dates are exogenous, in that the user of the affected software cannot influence them. At the Patch Implementation time the user implements the patch of the vendor. This time is endogenous as the user can choose when to implement the patch.
Vulnerability Lifecycle Events
Note that the sequence of the exploit, disclosure, and patch time is not fixed. Both, the exploit- and the patch-time can be before, at, or after the discovery time. However, discovery time is always the first of all these times. In the table below we discuss these points in time individually.

Discovery Time

Discovery Date Scatter Plot Exploit Date Scatter Plot Patch Date Scatter Plot

Exploit Time

Disclosure Time

Patch Time