Setting the scene in vulnerability work

No ratings

Presented at AUScert 2010 by

Software faults and vulnerabilities are complex issues that involve actors with various goals as well as multitude of soft and hard dependencies. Vulnerabilities have come to involve most of the society with the advent of prevalent usage of information technology. Principal activity (past tense/present perfect tense) The purpose of this presentation is to present a brief summary of the current vulnerability landscape. Methodology (past tense) The presentation draws on the experiences of ten years of vulnerability discovery and coordination. Results (past tense) The most important aspect to realise about vulnerability work is that it is a problem of resource limitations. The researchers try to maximise their productivity in terms of vulnerability sophistication, volume and impact, all considered hard research problems. Coordinators and reporters try to relay this information to the vendor in a clear and concise manner, while avoiding false positives, hype and needless pressure. Developers and vendors have goals ranging from protecting their customers to making revenue. Conclusions (present tense/tentative verbs/modal auxiliaries) The industry is currently mostly failing to produce dependable, secure and safe code. The current state of the art in vulnerability work highlights the need for developing methods for coping with vulnerability.