The Life of a 0-Day

No ratings

Presented at DallasCyberSecurityConference 2019 by

We’ve all heard stories about advanced nation-states leveraging zero-days to exploit a previously unknown security vulnerability. Perhaps the most infamous example is Stuxnet (with its four zero-days) that went undetected for an estimated five years prior to being discovered. However, that does not mean the ability to develop exploits for zero-day vulnerabilities is reserved only for well-financed state-sponsored actors.We will cover the definition of zero-days, their types (including immortal, quasi-alive, etc.), the cost of developing or buying zero-day exploits and their lifetime. What is the life expectancy of zero-day exploits and their underlying vulnerabilities? You are up for a surprise (or two)!Finally, we will embark on a discussion of whether the government should stockpile zero-days or disclose them as soon as they are discovered. This talk leverages data from the first large-scale study of zero-days.