NSS Labs Vulnerability Threat Report Sees Significant Rise in Vulnerability Disclosures in 2012 Afte

NSS Labs Vulnerability Threat Report Sees Significant Rise in Vulnerability Disclosures in 2012 After 5 Years of Decline

ID: 225883

Research Shows Overall Vulnerability Disclosures Rose a Staggering 26% in 2012; Vulnerabilities in SCADA Systems Protecting Critical Infrastructure Have Skyrocketed 600% Since 2010


(firmenpresse) - AUSTIN, TX -- (Marketwire) -- 02/04/13 -- NSS Labs today released a new 2012 Vulnerability Threat Report, analyzing data on threat and vulnerability trends over the past 10 years and revealing that after a 5 year decline, the number of vulnerabilities disclosed in 2012 rose 26% compared to 2011. This reversal, along with recent announcements from the Common Vulnerabilities and Exploits Project (CVE) that they plan to change their vulnerability identification syntax in order to classify more than 9,999 per year, indicate that vulnerability numbers are expected to increase steadily, despite massive secure software investment across the software industry.

Watch the Video -
Read the Report -

NSS's research yielded several key conclusions:

: While still a relative low total number (124 in 2012), vulnerabilities within information control systems (ICS) and supervisory control and data acquisition (SCADA) systems have grown by 600% since 2010 and nearly doubled from 74 to 124 from 2011 to 2012 alone. These systems control industrial, infrastructure and facility-based processes such as electric grids, water supplies, power plants, pipeline, etc. -- all of which represent high value targets to cybercriminals wishing to cause large-scale disruption or damage. With tools now available to easily identify internet-facing ICS/SCADA systems, NSS expects that the arms race has only just started and we expect security issues with these systems to continue to increase.

: On average, around one percent of vendors account for 31 percent of the vulnerabilities disclosed per year and only one of the top 10 vendors -- Microsoft -- managed to decrease its vulnerability disclosures in 2012 compared to its average number of disclosures in the previous decade. This small number of vendors represents the most prevalent software products in everyday private and enterprise use -- which is visualized in the video above.

: Vulnerabilities disclosed in 2012 affected over 2,600 products from 1,330 vendors -- 73% of these were new vendors who had not had a vulnerability disclosure with the previous two years. These new vendors accounted for 30% of the total vulnerabilities disclosed in 2012. While reoccurring vendors may still represent the bulk of vulnerabilities reported, research shows that the vulnerability and threat landscape continues to be highly dynamic with new vendors continually emerging as technologies (and threats) evolve.





: In 2012, 9.2% of disclosed vulnerabilities had a CVSS (common vulnerability scoring system) base score of 9.9 or more paired with a low attack complexity. This combination of a highly critical vulnerability that is fairly easy to attack or exploit represents a "perfect match" for cybercriminals who can now do more damage with less skill. The top 10 vendors with this type of vulnerability represent major types of software used every day by consumers, businesses, government agencies and other organizations, including popular web browsers, plugins and media players, or operating systems. One notable exception is Advantech, a producer of industry control/SCADA systems.

: Two of the most well recognized and long running vulnerability purchase programs, iDefense VCP and HP Zero-Day Initiative (formerly TippingPoint), both lost more than half of their market share in 2012. This correlates with an overall change in how vulnerabilities (and exploits) are being bought and sold as the marketplace for each is rapidly expanding.

"While vulnerabilities in 2012 haven't returned to the all-time high levels we saw in 2006, it's significant that after 5 years of decline, the number of disclosed vulnerabilities rebounded sharply and jumped 26% in one year," said Stefan Frei, Research Director at NSS Labs. "It is not just the number of vulnerabilities that matters, however. The level of criticality, how easily a vulnerability can be exploited, and the types of software they affect are all part of determining how serious a threat any single vulnerability might pose and these are trends we continue to watch. The growing number of vulnerabilities being disclosed in ICS/SCADA systems, in particular, is very concerning -- not only for vendors developing these systems, but also for governments around the world that would have to respond to any catastrophic consequences from attacks against critical infrastructures."

To read more NSS Labs research and reports, visit .

NSS Labs, Inc. is the world's leading information security research and advisory company. We deliver a unique mix of test-based research and expert analysis to provide our clients with the information they need to make good security decisions. CIOs, CISOs, and information security professionals from many of the largest and most demanding enterprises rely on NSS Labs' insight, every day. Founded in 1991, the company is located in Austin, Texas. For more information, visit .

© 2013 NSS Labs, Inc. All rights reserved. All brand, product and service names are the trademarks, registered trademarks, or service marks of their respective owners.



Embedded Video Available:





ReseAnne Sims
Sr. Manager, Public Relations
NSS Labs
Phone: +1 (832) 741-7373

Weitere Infos zu dieser Pressemeldung:

Themen in dieser Pressemitteilung:


Unternehmensinformation / Kurzprofil:
drucken  als PDF  an Freund senden  REMINDER: Media Alert: Kilopass to Exhibit at Common Platform Technology Forum 2013 WorkForce Software Appoints Seasoned Business Executive as New Vice President of Global Services
Bereitgestellt von Benutzer: MARKETWIRE
Datum: 04.02.2013 - 15:00 Uhr
Sprache: Deutsch
News-ID 225883
Anzahl Zeichen: 0

contact information:
Town:

AUSTIN, TX



Kategorie:

Hardware



Diese Pressemitteilung wurde bisher 267 mal aufgerufen.


Die Pressemitteilung mit dem Titel:
"NSS Labs Vulnerability Threat Report Sees Significant Rise in Vulnerability Disclosures in 2012 After 5 Years of Decline"
steht unter der journalistisch-redaktionellen Verantwortung von

NSS Labs (Nachricht senden)

Beachten Sie bitte die weiteren Informationen zum Haftungsauschluß (gemäß TMG - TeleMedianGesetz) und dem Datenschutz (gemäß der DSGVO).

NSS Labs Adds Jason Brvenik as Chief Technology Officer ...

AUSTIN, TX -- (Marketwired) -- 01/18/17 -- NSS Labs, Inc., the global leader in operationalizing cybersecurity, today announced that Jason Brvenik has joined NSS Labs as Chief Technology Officer (CTO). He will serve on the NSS Labs Executive Committ ...

Alle Meldungen von NSS Labs



 

Werbung



Facebook

Sponsoren

foodir.org The food directory für Deutschland
Informationen für Feinsnacker finden Sie hier.

Firmenverzeichniss

Firmen die firmenpresse für ihre Pressearbeit erfolgreich nutzen
1 2 3 4 5 6 7 8 9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z