Government Technology

    Digital Communities
    Industry Members

  • Click sponsor logos for whitepapers, case studies, and best practices.
  • AT&T Logo
  • McAfee
  • Net App

Report: Application Vendors Take Too Long to Fix Dangerous Security Holes



September 24, 2009 By

Researchers have found that vendors take at least twice as long to fix vulnerabilities in popular client-side programs and Web sites than they do the holes in supporting operating systems, even though the flaws in applications like QuickTime, Flash and Microsoft Office are the most vulnerable and exploited.

"When an operating system vulnerability comes out for Windows, it gets patched fairly quickly. But when a vulnerability comes out for Adobe Reader, for example, or for QuickTime or even for Microsoft Office, people apply these patches in a much slower rhythm," said Wolfgang Kandek, chief technical officer for Qualys, a provider of security risk and compliance technology.

The information he speaks of came from the Top Cyber Security Risks report released this month from the SANS Institute, an organization that provides security training and research. Researchers from Qualys and TippingPoint, another provider of network security solutions, worked with SANS researchers to compile the report's data.

The research data spans March 2009 to August 2009 attack information from 6,000 organizations that TippingPoint monitors with intrusion prevention systems, and vulnerability data from 9 million systems compiled by Qualys, as well as additional information from SANS personnel. SANS plans to release a cyber-security risks report every six months to keep the data up to date.

Data reveals that application vulnerabilities exceed operating system vulnerabilities and that targets against Web applications made up more than 60 percent of the attacks observed on the Internet. These vulnerabilities were "being exploited widely to convert trusted Web sites into malicious Web sites serving content that contains client-side exploits." But client-side programs are also vulnerable.

"The two big places that's happening is on these trusted Web sites where people wrote the applications that support the Web site, but they left flaws in their programs that cause all of their visitors to the Web site to be infected," said Alan Paller, the director of research for SANS. "The other one is flaws in client software like Flash and Adobe Reader and Microsoft Office. Those have vulnerabilities that are not being patched."

The report didn't delve into why it takes so much longer to rectify these types of vulnerabilities, but Kandek said he believes that IT administrators are simply more focused on securing operating systems than they are on securing applications.

And as to why the applications have so many holes in the first place, he theorizes that programmers are pushed more to write code that performs than code that's secure.

"Software in the past was developed to provide you the functions that you require. That is the focus -- does it print well, does it format well, does it allow me to do this and this," Kandek said. "The security and development -- there wasn't really a focus."

The SANS Institute hopes that this report and its future editions will help inform and educate programmers in the vendor community to focus more on security when they write their programs.

 


| More

Comments


Add Your Comment

You are solely responsible for the content of your comments. We reserve the right to remove comments that are considered profane, vulgar, obscene, factually inaccurate, off-topic, or considered a personal attack.

In Our Library

White Papers | Exclusives Reports | Webinar Archives | Best Practices and Case Studies
Identity and Access Management Considerations
Gain insight into enterprise identity and access management (IAM) trends and a unified approach that can simplify identity and access management before, during, and after your organization implements cloud-based services.
Document Driven Process Automation and Human Services
By the Center for Digital Government

Read this Center for Digital Government issue to find out how document-driven process automation can drastically accelerate workflow in state and local government human services agencies.
Using Wireless Technology to Manage and Optimize Government Fleets: Saving Money, Generating Revenues, and Increasing Safety
Using Wireless Technology to Manage and Optimize Government Fleets: Saving Money, Generating Revenues, and Increasing Safety. The paper discusses the challenges federal, state and local government agencies currently face with their government fleets; how mobile technology can help; considerations when selecting a mobile solutions partner; and the benefits of choosing Sprint. Specifically, Frost & Sullivan highlights Sprint’s fleet expertise, its powerful networks, and advanced partnerships that work in concert to provide government fleets with the ability to: Save money, Generate new revenues, Enhance safety, Help the environment, Increase the availability and transparency of information to the public
View All

RSS

Digital Communities members get access to our collaboration task forces

427 Members

77 Discussions

84 Files

Latest members Become a member

Digital Communities members get access to our collaboration task forces

669 Members

145 Discussions

150 Files

Latest members Become a member

 


Featured White Papers & Reports

CIOs Redefine Local Government and Industry Relations

Based off of discussions of the Digital Communities Large Jurisdiction Chief Information Officer (CIO) Working Group, this white paper aims to answer the question, "In today's economic, political and business environment, what constitutes a successful relationship between government and industry?" Cause for Optimism identifies and clarifies the issues that separate government and industry, and begins to find an answer to the question necessary for both to enjoy a successful and prosperous future.


View Full Library

Events

GTC East

Don't miss this opportunity to see the latest in digital government solutions, keep abreast of current policy issues and network with key government executives, technologists and industry specialists.

View All Events