Vunerabilities, Exposures, Attacks and the Enterprise [Business Tutorial]

No ratings

Presented at AUScert 2008 by

Not all of the newest, coolest security issues involve Web 2.0. In 2007 alone, approximately 7000 vulnerabilities were publicly reported in the Common Vulnerabilities and Exposures (CVE) list. Due to the volume of raw data, interesting discoveries can be lost in the noise, especially if they aren't published by well-known researchers for software with large installation bases. These problems might fly under the radar today, but they could become the research fad of tomorrow. This talk will start with an up-to-the-minute vulnerability classes and attacks that have yet to be well-documented. It will briefly cover common analytical errors and terminology issues that prevent a deeper appreciation of the weaknesses that lead to security problems. It will introduce the basic tenets of vulnerability theory, which is a framework for understanding and reasoning about vulnerabilities, including a vocabulary for discussing important security concepts. Vulnerability theory can be used to anticipate new security issues, instead of waiting and hoping that we'll notice them the next time we dare to drink from the Internet fire hose. As the threat of attacks against organizations broadens from the networks and commercial software to include individual software applications and infrastructure of all types, there is an increasing need for assurance that the software products acquired or developed are free of known types of security weaknesses and resistant to known attacks. To accelerate closing the gap on vulnerabilities and foster assurance that software has been tested for known security issues the Common Weaknesses Enumeration (CWE) - a dictionary/encyclopedia - is being developed that can be used to look for weaknesses in code, design, or architecture, guide the development of secure software, as well as to teach and train software developers about the code, design, or architecture weaknesses that they should avoid. This talk will also cover the Common Attack Pattern Enumeration and Classification (CAPEC), which is developing a collection of common attack patterns to support security requirements definition, threat modeling, attack resistance through architectural risk analysis and secure code review, and targeted risk-based security testing of software as well as teaching software developers to understand and leverage the attackers perspective. Combined, the CWE and CAPEC efforts support the effective and efficient creation of secure software testing target lists. Together CVE, CWE, and CAPEC provide the enterprise with tools, techniques and methods for planning, measuring, and managing their software assets and processes in a more scalable and consistent manner that is agnostic to their specific vendor technologies and suppliers, which opens the door to consistency and leverage across industries and throughout the various portions of an enterprise.