The Laws of Vulnerabilities: Which security vulnerabilities really matter?

  • Authors:
  • Gerhard Eschelbeck

  • Affiliations:
  • Qualys, Inc, USA

  • Venue:
  • Information Security Tech. Report
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

New security vulnerabilities are discovered on a daily basis. With each new announcement, the same questions arise. How significant is this vulnerability? How prevalent? How easy is it to exploit? Due to a lack of global vulnerability data, answers are hard to find and risk rating is even more difficult. The Laws of Vulnerabilities are the conclusions of analyzing statistical vulnerability information over a three-year period. Those vulnerabilities have been identified in the real world across hundreds of thousands of systems and networks. These data are not identifiable to individual users or systems. However, it provides significant statistical data for research and analysis, which enabled us to define and publish the Laws of Vulnerabilities (http://www.qualys.com/research/rnd/vulnlaws/).