printlogo
ETH Zuerich - Homepage
Computer Engineering and Networks Laboratory (TIK)
 

Publication Details for Inproceedings "The speed of (In)security"

 

 Back

 New Search

 

Authors: Stefan Frei, Martin May
Group: Communication Systems
Type: Inproceedings
Title: The speed of (In)security
Year: 2006
Month: August
Pub-Key: FM06_a
Book Titel: Blackhat Conference 2006
Keywords: network security, vulnerability, risk management
Publisher: Blackhat
Abstract: To be able to defend against IT security attacks, one has to understand the attack patterns and henceforth the vulnerabilities of the attached devices. But, for an in-depth risk analysis, pure technical knowledge of the properties of a vulnerability is not sufficient: one has to understand how vulnerabilities, exploitation, remediation, and distribution of information thereof is handled by the industry and the networking community. In the research, we examined how vulnerabilities are handled in large-scale by analyzing 80,000+ security advisories published since 1995. This huge amount of information enables us to identify and quantify the performance of the security and software industry. We discover trends and discuss their implications. Based on the findings, we finally propose a measure for the global risk exposure.
Location: Las Vegas, USA
Resources: [BibTeX] [ External LINK ] [Slides as PDF]

 

 Back

 New Search