On mySimon: Body Solid EXM 3000LPS
BNET Business Network:
BNET
TechRepublic
ZDNet

June 22nd, 2007

Flaw counting comparisons useful but fall short of true picture

Posted by Ryan Naraine @ 6:34 am

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, Microsoft, Open source, Passwords, Patch Watch, Pen testing, Responsible disclosure, Viruses and Worms, Vulnerability research, Windows Vista, Zero-day attacks

Tags: Security, Linux, Vulnerability, Microsoft Windows, Microsoft Corp., Flaw, Ryan Naraine

The Windows vs Linux security report card that I wrote about from TechEd two weeks ago is officially out and Microsoft has stepped up its PR campaign to argue that Windows Vista has a “lower vulnerability fix and disclosure rate” than competitive Linux distributions.

Jones released the study (download PDF) and posted a primer with details on the methodology used to compare vulnerabilities disclosed and fixed in the first six-month period after a product ships.

In all four cases studied for the 6 month period after ship, Windows Vista appears to have a lower vulnerability fix and disclosure rate than the other products analyzed, including the reduced Linux installations. This affirms the early results that we found after 90 days and provides a supporting indicator that the Microsoft Security Development Lifecycle process and heightened focus on security is having a positive impact on Microsoft Windows in terms of fewer vulnerabilities.

He also, for the first time, broke out “high severity” vulnerabilities in the comparison and again Jones found that Windows Vista and even Windows XP fared better than Linux distribution workstations.

The controversial studies have been dismissed as biased propaganda — see Talkback comments here and here — from Redmond (Jones is security strategy director in Microsoft’s Trustworthy Computing group) but in my mind it’s a useful attempt to dig into the publicly available numbers to find a measurement.

The problem I have with Jones is that his flaw counting ignores silently fixed vulnerabilities and makes assumptions on security based only on publicly documented vulnerabilities.

As a policy, Microsoft routinely ships silent fixes within its security bulletins if flaws are discovered internally. These are never assigned CVE numbers and will never appear in these comparison reports from Jones.

When I asked Jones and other Microsoft security staffers about ignoring silent fixes in these reports — which could significantly increase the Windows flaw count — they argued that everyone (including Linux distributions) issues patches with silent fixes. Additionally, Jones claimed that vulnerabilities discovered and fixed without help from external researchers do not put anyone at risk since they are only found internally.

This argument ignores the dramatic rise in zero-day attacks that use undocumented flaws/exploits to target .gov, .mil and other business networks. Try telling an enterprise that’s been hit with a zero-day that his loss is less important because it’s not a widespread risk, you just might get a punch in the nose.

So, while Jones’ reports make for good discussion fodder, take them with a grain of salt. Hey, even Jones admits that he’s biased.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 116 Talkback(s)
So
Being under a supervision and a consent decree is being found not guilty? I guess Standard Oil and IBM weren't found guilty either. Oh, and I guess South Korean and the EC decisions against them mean ... (Read the rest)
Posted by: zkiwi Posted on: 06/27/07 You are currently: a Guest | | Terms of Use
It simply doesn't matter. Better security  No_Ax_to_Grind | 06/22/07
i hate myself for this...  Monkey_MCSE | 06/22/07
Not really  No_Ax_to_Grind | 06/22/07
If their issue is not wanting to alert hackers  Michael Kelly | 06/22/07
No argument from me really, but...  No_Ax_to_Grind | 06/22/07
You don't even have to get that detailed  Michael Kelly | 06/22/07
Like I said, no real argtument from me. (nt)  No_Ax_to_Grind | 06/22/07
Yeah...  zkiwi | 06/22/07
yeah  xuniL_z | 06/23/07
HAHAHA, yeah, just spin yourself right around  Kid Icarus-21097050858087920245213802267493 | 06/23/07
since you brought it up,  xuniL_z | 06/23/07
Uhmmm OK?  Kid Icarus-21097050858087920245213802267493 | 06/25/07
Spin?  zkiwi | 06/23/07
well  xuniL_z | 06/23/07
Yes, delusional  zkiwi | 06/24/07
wrong  xuniL_z | 06/24/07
Keep on spinning  zkiwi | 06/24/07
keep being trite.  xuniL_z | 06/24/07
He is full of it!  Linux User 147560 | 06/22/07
Pitifull attempt to distort the truth!  ShadeTree | 06/22/07
i've said it before...  Monkey_MCSE | 06/22/07
You say I am the daft one...  ShadeTree | 06/22/07
I understood his post.  I am Gorby | 06/23/07
Man did you totally miss the short bus on this one!  Linux User 147560 | 06/22/07
Your the one that missed the bus and the story  ShadeTree | 06/22/07
Yes they are...  Linux User 147560 | 06/22/07
Yes you can do this!  ShadeTree | 06/22/07
By your line of argument  Michael Kelly | 06/22/07
No you can't...  Linux User 147560 | 06/22/07
Oh and one more thing  Linux User 147560 | 06/22/07
Sure you can fix OSS software silently  xuniL_z | 06/23/07
Why argue  DemonX | 06/22/07
Honesty and responsibility  Michael Kelly | 06/22/07
Because that is not the point  Kid Icarus-21097050858087920245213802267493 | 06/23/07
Sysprogs always check the Known Error Logs (KEL)  I am Gorby | 06/23/07
There is no difference.  xuniL_z | 06/23/07
You read it again....  xuniL_z | 06/25/07
Message has been deleted.  zetra001 | 06/22/07
MS reports Windows better! Surprise!  bahamude | 06/22/07
You fall into your own trap  mdemuth | 06/22/07
Your "yard stick" is meaningless in the real world  No_Ax_to_Grind | 06/22/07
Plus . . .  JLHenry | 06/22/07
Microsoft right to patch flaws without notice.  ShadeTree | 06/22/07
The other side of the coin  Ryan NaraineZDNet Moderator | 06/22/07
You're right on target Ryan , keep up the good work .  I'm Ye, the MS SHILL . | 06/22/07
The answer to the big question...  Kid Icarus-21097050858087920245213802267493 | 06/22/07
I would think  DemonX | 06/22/07
Himmler said...  I am Gorby | 06/23/07
You should be more carefull also  ShadeTree | 06/25/07
Yep! Got me.  I am Gorby | 06/25/07
One more to add to that side of the coin  tic swayback | 06/22/07
lol  Jack-Booted EULA | 06/22/07
And ....  Linux_4u! | 06/22/07
I disagree.  ShadeTree | 06/22/07
Somebody always knows there is a flaw  Michael Kelly | 06/22/07
When that somebody is the person responsible ...  ShadeTree | 06/22/07
But how did THAT person find out  Michael Kelly | 06/22/07
This story piggybacks off of Ryan's initial ...  ShadeTree | 06/22/07
Re: This story piggybacks off of Ryan's initial  Michael Kelly | 06/22/07
Shadey, you're having a bad day!  I am Gorby | 06/23/07
One more time  zkiwi | 06/22/07
They know by testing the patches and ..  ShadeTree | 06/22/07
Yes  zkiwi | 06/23/07
zkiwi, please  xuniL_z | 06/23/07
Missing the point completely  tic swayback | 06/22/07
I am saying the PR campaign compares a ...  ShadeTree | 06/22/07
But you are also saying that statistic is meaningless  tic swayback | 06/22/07
Dude, get your head out of your ARSE!!  Kid Icarus-21097050858087920245213802267493 | 06/22/07
You have managed to drag the discussion ....  ShadeTree | 06/22/07
Congratulations, on completely missing the point!!  Kid Icarus-21097050858087920245213802267493 | 06/22/07
Flaws that have been . . .  JLHenry | 06/22/07
Elliminate the softener  John L. Ries | 06/22/07
Unreasonable  Yagotta B. Kidding | 06/22/07
Trust must be earned  tic swayback | 06/22/07
Then why do you trust Apple so much?  ShadeTree | 06/22/07
I trust no one  tic swayback | 06/22/07
Rules of evidence  Yagotta B. Kidding | 06/22/07
I can handle withholding of information  Michael Kelly | 06/22/07
Corporations  John L. Ries | 06/22/07
What's obvious is that even after  xuniL_z | 06/26/07
So  zkiwi | 06/27/07
How does not knowing about an undisclosed ....  ShadeTree | 06/22/07
Good points, but not quite right  Ryan NaraineZDNet Moderator | 06/22/07
You are left to decide the patch based on what is documented.  ShadeTree | 06/22/07
and if the silent fix stops one of your  deaf_e_kate | 06/22/07
Expensive Complexity  Mikael_z | 06/23/07
Microsoft does test their patches ...  ShadeTree | 06/25/07
Oh count the number of Windows installs that have been borked  Linux User 147560 | 06/22/07
If you are testing the patches your install does not ...  ShadeTree | 06/22/07
Are you completely missing the point  deaf_e_kate | 06/22/07
They are talking about silent fixes that are ...  ShadeTree | 06/25/07
Side-effects and mitigation  mosborne | 06/22/07
If the bad guys are not told about the flaw ...  ShadeTree | 06/22/07
If the good guys are not told about the flaw ...  Michael Kelly | 06/22/07
Oh yes they do.  ShadeTree | 06/25/07
That's quite naive  mosborne | 06/22/07
If the bad guys know about the flaw ...  ShadeTree | 06/25/07
It might be somewhat different  tombalablomba | 06/22/07
Message has been deleted.  Intellihence | 06/22/07
LOOK EVERYONE!@#*&#@#! HE MENTIONS ME!!!  Loverock Davidson | 06/22/07
Don't let it get to your head L.D.  I'm Ye, the MS SHILL . | 06/22/07
Yep, he named the retard  jasonp@... | 06/22/07
You didn't have to be quite so hard on L.D. you know .  Intellihence | 06/22/07
The tool of the century won't go away.  xuniL_z | 06/23/07
If my posts are zero then why do you continue to respond to them ?  Intellihence | 06/25/07
Flaw count  hairyR | 06/22/07
Serves the security industry right.  osreinstall | 06/22/07
Inspiration  THEE WOLF | 06/22/07
Easy Enough  daMan25 | 06/22/07
Unbiased Observations from a month of reading  Too_Busy_To_Be_Here | 06/23/07
It's sick Microsoft won't follow up on their products.  HypnoToad72 | 06/23/07
"Microsoft Frowns on iDefense Hacking Challenge"  ruped24 | 06/23/07
Is this really a good thing?  brokndodge@... | 06/24/07
No hidden flaws, just hidden greatness...  Mike Cox | 06/24/07
9.5  shallow_diver | 06/25/07
Dude, you are the WOW of ZDNet!!  Kid Icarus-21097050858087920245213802267493 | 06/25/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads