07 Feb 2011
Security firm TippingPoint has announced the results of its first Zero Day Initiative, which names and shames vendors with vulnerabilities that go unpatched for more than six months.
IBM was the biggest offender with nine vulnerabilities, followed by Microsoft with five and HP with four. Vendor-specific bug reports are now being posted on the TippingPoint blog.
Aaron Portnoy, manager of security research at TippingPoint, told V3.co.uk that the results of the first six months had been very encouraging.
The company had initially compiled 186 vulnerabilities for the list, but only 22 remained unpatched at the end of the first six months.
"Surprisingly, a lot of companies got onboard. It's been phenomenal getting the message across. Researchers are also supportive, although some said we were giving the software vendors too much time to fix flaws," Portnoy said.
The speed and efficiency in responding to flaws is helped greatly when the vendor has a security response team in place, according to Portnoy, who praised Adobe in particular for putting together a good unit, made up in part by ex-Microsoft employees.
One of the most surprising results of the Zero Day Initiative was the number of vulnerabilities that were discovered almost simultaneously. One particular flaw was discovered and reported by seven different researchers, giving a good indication that hackers will find them too.
The project is necessary because it forces companies to fix flaws and lets researchers get on with finding security holes without having to deal with large companies, Portnoy explained.
"Trying to force a big vendor to do something is a power struggle. We are part of a big company. We disclose more vulnerabilities than anyone else and have the clout to force vendors to change," he said.
"Many researchers with the Zero Day Initiative are converts. They don't want to deal with vendor disclosure."
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
About Us WorldPay provides a globally connected, locally...
About Us WorldPay provides a globally connected, locally...
SQL Server Developer - Our client, an international...
IT Technical Service Delivery Manager / ITIL / Reigate...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?