printlogo
ETH Zuerich - Homepage
Computer Engineering and Networks Laboratory (TIK)
 

Publication Details for Inproceedings "0-Day Patch - Exposing vendors (in)security performance"

 

 Back

 New Search

 

Authors: Stefan Frei, Bernhard Tellenbach, Bernhard Plattner
Group: Communication Systems
Type: Inproceedings
Title: 0-Day Patch - Exposing vendors (in)security performance
Year: 2008
Month: March
Pub-Key: frei2008c
Book Titel: BlackHat Europe 2008
Keywords: vulnerability lifecycle, black hat, exploit date, insecurity performance, security, 0-day patch rate, 0-day, patch
Abstract: We measure and compare the performance of the vulnerability handling and patch development process of Microsoft and Apple to better understand the security ecosystem. We introduce the 0-day patch rate as a new metric; being the number of patches a vendor is able to release at the day of the public disclosure of a new vulnerability. Using this measure we can directly compare the security performance of Microsoft and Apple over the last 6 years. We find global and vendor specific trends and measure the effectiveness of the patch development process of two major software vendors over a long period. For both vendors we find that major software development projects (such as a new OS release or Service Pack) consumes resources at the cost of patch development. Our data does not support the common belief that software from Apple is inherently more secure than software from Microsoft. While the average number of unpatched vulnerabilities has stabilized for Microsoft, Apple has bypassed Microsoft and shows an increasing trend. We provided an insight into the vulnerability lifecycle and trends in the insecurity scene based on empirical data and analysis. To properly plan, assess, and justify vulnerability management knowledge of the vulnerability ecosystem is important.
Location: Amsterdam
Resources: [BibTeX]

 

 Back

 New Search