Bringing law to the security jungle

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

A plan to make it easier for companies to determine how hard they could be hit by security flaws is ready for prime time, according to its backers.

The Common Vulnerability Scoring System plan calls for a unified approach to rating vulnerabilities in software, to replace the proprietary methods many technology companies and security vendors use when determining the impact of a flaw.

"We want to bring order to the chaos," said Mike Caudill, chairman of the Forum of Incident Response and Security Teams (FIRST) which is pushing for adoption of the new Common Vulnerability Scoring System (CVSS). "The ultimate goal is to have a system that will help the user appropriately react to a vulnerability."

CVSS was developed under the auspices of the National Infrastructure Advisory Council, which advises US President Bush about the security of information systems for critical infrastructure. FIRST, a worldwide consortium of security incident response teams such as the United States Computer Emergency Readiness Center, coordinates further CVSS development.

On Monday, FIRST plans to announce a push for wide-scale adoption of CVSS. Backers believe the rating system is ready to move into more general use after being a work-in-progress for the past year and a half. It was released publicly in late February, when a group of about 30 companies started testing it.

"Now is the time to move to the next phase of deploying CVSS and getting additional vendors on board," Gerhard Eschelbeck, one of the designers of the rating scheme and chief technology officer at vulnerability management company Qualys, said Friday.

CVSS goes beyond today's severity ratings, such as the familiar "critical" and "important" found in security bulletins from Microsoft. The new scoring system, which uses numbers between 1 and 10, enables organizations to calculate the specific risk to their own environment by adding information related to their IT systems. This could help them prioritise patches.

In addition to letting companies add their own environmental metric to the risk equation, CVSS also takes into account factors such as the availability of attack code and security patches, which can have an impact on the risk posed by a vulnerability. Current rating schemes typically are limited only to certain aspects of the vulnerability — for example, whether an attacker could remotely compromise a system and how easily a flaw can be exploited.

Risk assessment
If CVSS is widely adopted, an enterprise risk manager or security professional could use the system to determine which flaws need fixing first, Caudill said.

"It would allow an organisation to compare vulnerabilities from multiple vendors, on multiple platforms and potentially affecting different parts of an organization, and have a common metric for assessing the risk," he said.

FIRST is calling on the software industry to include CVSS scores in its security advisories, said Caudill, who is also a member of Cisco's product security incident response team. "It gets everybody on the same page," he said. Cisco already provides CVSS scores on its MySDN security site but not in its own advisories, Caudill said.

Several security vendors — including Symantec, ISS and Qualys — support CVSS and will adopt it in their own products, representatives of the companies said.

"We're strong supporters of having open standards in this area," said Vincent Weafer, a senior director at Symantec Security Response. "Prior to this, each vendor had their own standards on scoring vulnerabilities, which makes it very confusing for enterprises making critical decisions on which patches to deploy first."

Qualys' Eschelbeck agreed. "Users are looking to CVSS-type scoring, so we can take away a burden from them," he said.

>Microsoft's stance
However, Microsoft is sticking to its own rating scheme, Kevin Kean, director of Microsoft's security response centre, said in a statement provided by representatives of the software giant.

"We recognise that some vendors and security organizations within the industry utilize varying severity rating systems which do serve practical purposes for their objectives. Our customers have told us that the severity rating system we implemented in 2002 is valuable in helping them assess their level of risk and utilise the resources we've made available to them to help protect their systems," Kean said.

Still, if customers start requesting that Microsoft adopt CVSS, it will, Kean said.

With Microsoft giving CVSS the cold shoulder, it could be a while for the system to be broadly adopted, said John Pescatore, a vice-president at researcher Gartner.

"Since Microsoft is pretty much the largest source of vulnerabilities on desktop PCs, if they don't use CVSS, it will slow down others," Pescatore said. "I think security service and tool vendors will start to use it sooner."

While there is some benefit in CVSS, Pescatore thinks its role in helping IT managers decide which patches to apply first is being overstated. "No scoring system will do that," he said. "But having a standard rating methodology used by most vendors will be a good thing for IT."

If users see value in the new scoring system, they can put pressure on software companies to start using it, Pescatore said. "If a few large product vendors, like Cisco, start to use it, I think that by 2007, Microsoft would start hearing from its customers that they want Microsoft to use it," he said.

Talkback

Since MS is the king of flaws and vulnerabilities and since they don't adhere to WWW standards, why would they be interested in caring what their customers want? Just do your own thing and let the customer worry about the problems. After all they have signed the EULA. it's their problem now.

via Facebook 19 September, 2005 15:15
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

8 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

16 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

18 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

18 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

20 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

22 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

23 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

24 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

24 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

1 day ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint