Hacker
Hackers are targeting vulnerabilities for financial reasons

IBM urges rethink on vulnerability assessments

Common Vulnerability Scoring System too technically focused, says Big Blue

Phil Muncaster

The security industry needs to reprioritise its response to disclosed software vulnerabilities in order to determine more effectively when emergency patching is most needed, according to the latest annual security trends report from IBM.

The 2008 X-Force Trends and Risk report found that a number of critical vulnerabilities disclosed in 2008 did not actually see widespread exploitation in the field.

Advertisement

IBM argues that the current Common Vulnerability Scoring System focuses on the technical aspects of a vulnerability, such as severity and ease of exploitation, and does not acknowledge that the main motivation for online criminals today is economic.

"We realise that cyber criminals are motivated by money, and we need to fully consider how attackers balance the economic opportunity of a vulnerability against the costs of exploitation," said Kris Lamb, senior operations manager of X-Force research and development for IBM Internet Security Systems.

"If the security industry can better understand the motivations of computer criminals we can be more precise about determining when widespread exploitation of a vulnerability will take a long time to emerge, and when it is unlikely to ever emerge. This analysis could result in more efficient use of time and resources."

The report also found a 13.5 per cent increase in newly discovered vulnerabilities last year compared to 2007, and that 53 per cent of all vulnerabilities disclosed during 2008 ended the year with no vendor patches issued.

In related news, a new wave of botnet activity has driven up spam volumes to the same levels they were before the McColo shutdown, according to new figures from managed security service provider MessageLabs.

"With botnets now responsible for as much as 80 per cent of all spam, the likelihood is that the increase in spam volumes in the last few days can be attributed to a new wave of activity from the Mega-D and Xarvester [botnets]," said Paul Wood, MessageLabs intelligence analyst at Symantec.

"As the botnet community becomes even more crowded, 2009 could be the year when spam levels reach an all-time high."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Microsoft bug

Single patch kicks off Microsoft's 2009

January fix addresses remote code flaw in Windows

Oracle

Oracle update includes 41 security fixes

Vendor will release major bug fix on the same day as Microsoft Patch Tuesday

Microsoft plans low-key Patch Tuesday

Single fix for January is in stark contrast to previous releases

Hackers take Israel-Palestine conflict online

Sites defaced with anti-Israeli messages and images

Related whitepapers

Related jobs

Most watched

Salesforce.com on the new Chatter service

Company explains the need for collaboration service

t-mobile logo

V3.co.uk weekly debrief, 20 Nov 09

This week we round up the major vendor conference events, plus T-Mobile sells customer data

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

t-mobile logo

V3.co.uk weekly debrief, 20 Nov 09

This week we round up the major vendor conference events,...

Apple iPhone apps

Top 10 articles, 20 Nov 2009

An App Store upset for Apple, and a scandal at...

Biz Stone

Twitter founder details commercial account plans

Biz Stone says paid-for accounts will give users access to...

Cloud computing

Enisa launches comprehensive cloud security report

EU security agency provides checklist for firms looking to vet...

Primary Navigation