You are here: silicon.com > Networks > LANs

LANs

Firms patching internet security holes faster

But still too slow securing LANS, says research…

By Robert Lemos

Published: 30 July 2004 09:30 GMT

Driven by the rapid onslaught of new security threats, network administrators are fixing the most prevalent flaws more quickly, according to a new survey.

The survey, released by vulnerability assessment firm Qualys at the Black Hat Security Briefings in Las Vegas, found the average half life of a vulnerability - the length of time it takes for half of assailable computers to be fixed - fell to 21 days in 2004 from 30 days in 2003.

However, the report found improvements only with systems connected directly to the internet. Administrators took longer to patch computers located within a local area network, believing they were safe.

Companies typically patched flaws in internal systems within 62 days in 2004; Qualys did not measure the time it took to patch internally in 2003.

"If you look at the challenge that companies have internally, it is a factor of 10 more complicated," said Gerhard Eschelbeck, CTO at Qualys.

The numbers are the best-case scenario for how quickly companies patch their systems. Qualys only collects anonymous data from its clients. The average company connected to the internet is likely to patch flaws much slower, Qualys said.

The slow rate at which companies update their systems has caused software makers, such as Microsoft, to look for better ways to secure customers that have not patched. Those companies need to start fixing their systems, Eschelbeck said.

"Knowing where your problems are is the first step, and then figuring out how critical each problem is the next," he said.

Moreover, if the average time companies stay connected to the internet shrinks, the window of time that worm writers can exploit vulnerabilities to spread their programs is lowered as well.

"We will see those worms hitting in the first two half lives," he said. "So the first two half lives are the most important times, because they act as a breeding ground."

Robert Lemos writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Peter Cochrane Peter Cochrane's Blog: How the telcos could save themselves Doomed network operators could thrive with a bit of innovation

Peter Cochrane Peter Cochrane's Blog: Facebook saves teen from prison Another unexpected impact of social networking


  • Jobs
Technical Analyst - SMS, SCCM, WSUS - Patch & Release

The role will involve the assessment of vulnerabilities, patch testing and application deployment via remote systems such as SMS/SCCM, WSUS and ...

Pre Sales Consultant / Solution Designer - Network Security

Their products provide global network visibility and are used to manage and secure the network and provide an accurate picture of what's connected to ...

Patch/Release Technical Specialist - Pathc Testing - SMS/SCCM

Patch/Release Technical Specialist - Patch Testing - SMS/SCCM Experienced Patch/Release Specialist required to join a high profile blue chip ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: