As security personnel met at this week's Black Hat Conference in Las Vegas, there was easy money to be made at the security vulnerability table.
Earlier this week, TippingPoint, 3Com's security division, announced it plans to reward security researchers and hackers who reveal information on newly discovered vulnerabilities as part of its Zero Day Initiative. TippingPoint will pay as much as US$2,000 for a verified vulnerability, company officials said.
Now iDefense, a security intelligence firm recently acquired by VeriSign, has raised the stakes, saying it will increase its payments for information on vulnerabilities.
The idea of the Zero Day Initiativ" is to ensure the "responsible" disclosure of security flaws to make the technology more secure for all users, according to David Enderle, director of security research for TippingPoint.
"We believe security researchers want to be recognized for their discoveries, but currently they don't often do it in a responsible manner. They announce the vulnerability to the world and then it is a race between the software company and the hacker community to either build a fix or exploit the code," he said.
A "zero day" attack occurs when a researcher discovers a vulnerability and discloses the flaw to the public without first notifying the vendor. This puts businesses and individuals at risk from the time of the disclosure until the affected vendor issues a patch. Some patches can be made in hours, but even then it takes time for affected machines to download the patches.
Under TippingPoint's program, it will inform the affected company of the vulnerability and wait for a patch to be ready before releasing the information to the rest of the world.
Companies like Microsoft have long resisted paying for information on vulnerabilities, believing a bounty will just encourage hackers to find flaws.
IDefense, which provides security intelligence services to large commercial and government clients, has long paid for vulnerability information to pass on to its customers.
"I think this initiative is a positive step for the industry. The goal of the ZDI is to proactively protect businesses as soon as possible against newly discovered vulnerabilities. That's an issue enterprises are very concerned about," said Victoria Fodale, a research analyst for In-Stat.
Vulnerability disclosure was also an issue for the Black Hat Conference itself when former Internet Security Systems (ISS) research analyst Michael Lynn quit his job to provide information on a serious Cisco Systems router vulnerability at the conference. ISS decided not to give a presentation on the flaw, but Lynn quit so that he could give the presentation.
The vulnerability has been patched by Cisco, but some companies don't update patches regularly. In his presentation, Lynn described a now-patched flaw in the Internetwork Operating System (IOS) software used to power Cisco's routers. Although Cisco was informed of the flaw by ISS, and patched its firmware in April, users running older versions of the company's software could be at risk, according to Lynn.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Everything you need to know about email and web security (but were afraid to ask)
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Gaining Competitive Advantage Through Enterprise Planning
The state of Middleware
Strategies for Eliminating .PST Files
Taking On Demand CRM Integration to the Next Level
IT Service Management Needs and Adoption Trends: An Analysis of a Global Survey of IT Executives
How to improve employee productivity in small and medium businesses
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
FrontRange Solutions launches HEAT Plus Mobile to reduce help desk costs and improve service management productivity 2008-12-02 15:15:00+11
AARNet Helps to Advance Indigenous Health 2008-12-02 12:44:00+11
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 2008-12-02 11:23:00+11
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 2008-12-02 10:09:00+11
Mornington Peninsula Shire implements Objective to manage knowledge and deliver service excellence 2008-12-02 09:56:00+11
Everything you need to know about email and web security (but were afraid to ask)
What you don’t know can destroy your business. It’s hard to imagine modern business without the internet but in the last few years it has become fraught with danger. Read on to discover how internet security can give your business a competitive advantage.












