Follow Us
RSS FeedSecurity

Average zero-day bug lasts a year

Average zero-day bug lasts a year

Bugs die when they become public or vulnerability gets patched....

The average zero-day bug has a lifespan of 348 days before it is discovered or patched, although some vulnerabilities survive for much longer, according to security vendor Immunity's CEO.

Zero-day bugs are vulnerabilities that have not been patched or made public. When discovered and not disclosed, these bugs can be used by hackers and criminals to break into corporate systems to steal or change data. As a result, there is a thriving market for zero-day bugs.


Related Articles
Wikileaks

Wikileaks

Wikileaks - fearless whistleblowers or irresponsible nuisances? Keep up to date with the latest developments. Read more


"Huge amounts of money are being offering to zero-day discoverers for their zero-days," said Justine Aitel [CQ], Immunity's CEO, speaking in Singapore at the SyScan '07 security conference.

Immunity, which buys but does not disclose zero-day bugs, keeps tabs on how long the bugs it buys last before they are made public or patched. While the average bug has a lifespan of 348 days, the shortest-lived bugs are made public in 99 days. Those with the longest lifespan remain undetected for 1,080 days, or nearly three years, Aitel said.

"Bugs die when they go public, and they die when they get patched," she said.

To protect their data, security executives need to dig out the zero-day bugs in their systems, Aitel said, noting that this is an area most companies ignore.

Companies should conduct internal and external security assessments to dig out zero-day bugs, Aitel said, adding that security managers need to win and keep the support of their CEOs for these efforts. They also need to work closely with their corporate legal department to avoid breaking the terms of licensing agreements that may otherwise prevent them from examining software for zero-day bugs.

"Always assume everything has holes. It's the truth: it does," she said.

Send to a friend

Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Does remote working affect how often you print?

Question of the day!

Does remote working affect how often you print?


% of Computerworld UK readers agree with you


Yes
TBC
No
TBC

What steps are you taking to address how/when/what you print?


123 characters remaining

Follow the conversation at @Think_Print


ComputerworldUK Knowledge Vault Hover to expand
Advertisement
X ComputerworldUK Share
Newsletter
Open
* *