On BNET: 5 classic computer pranks
BNET Business Network:
BNET
TechRepublic
ZDNet

September 24th, 2009

In search of a standard for displaying security threat levels

Posted by Ryan Naraine @ 6:32 am

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Data theft, Denial of Service (DoS), Locally Running Web Servers, Malware, Punditocracy, Rootkits, Spam and Phishing, Viruses and Worms

Tags: Security Company, Threat Level, Security, Ryan Naraine

GENEVA — A veteran security researcher today challenged the anti-malware industry to work on a standard way of assigning computer/Internet threat levels to present transparent helpful information to consumers and businesses.

During a presentation at the Virus Bulletin 2009 conference here, Fortinet project manager Bryan Lu discussed the current scenario where anti-malware vendor use different systems to display threat levels — either color-coded or using numbers and arrows — and suggested that vendors use existing data to make threat level indicators more useful and meaningful.

Lu argued that security vendors are already using sophisticated computation and logic to extract data from virus detections and spam e-mails but bemoaned the fact that only a part of this data is exposed to end users.

As explained by Gartner’s Greg Young, security vendors routinely offer different threat levels on the same day, which adds to confusion when businesses and consumers try to get a big picture view of the malware landscape.

To fix the problem, Fortinet’s Lu proposed a detailed system to compute a virus threat level, a spam threat level and a vulnerability threat level and made a strong argument that raw numbers can be computed to come up with a standard way of figuring out “severe,” “high,” “escalated” or “normal” threat levels.

“The vibrant security threat level indicators that end-users see on security vendors’ websites are certainly just the tip of the iceberg,” Lu said in a paper distributed at the conference.

“The underlying computation and logic shaped by the varying attributes comprises the much bigger part,” he added, noting that security vendors have already developed a standard way to extract the data on a “1 to 4″ scale.  However, Lu said only a part of this is exposed to the end user.

He presented a detailed way of figuring out the standard and called on security engineers in the audience fix one off the industry’s biggest confusion.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 2 Talkback(s)
This is similar to the fed's "threat level" thing
Why not leave it at max all the time? In theory, shouldn't you be
equally vigilant all the time??? The only thing that making it
variable accomplishes is that--after everyone has become so (Read the rest)
Posted by: Userama Posted on: 09/24/09 You are currently: a Guest | | Terms of Use
This is very old  markbn | 09/24/09
This is similar to the fed's "threat level" thing  Userama | 09/24/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline