Secure Coding mailing list archives
BSIMM: Confessions of a Software Security Alchemist (informIT)
From: gem at cigital.com (Gary McGraw)
Date: Thu, 19 Mar 2009 11:27:57 -0400
Hi Stephan, In my view, it would be even better to study the difference in external bug emphasis (as driven by full disclosure and the CVE) and internal bug emphasis (as driven by an organization's own top N list). Once again, this is a difference in emphasis you might put as "reactive" versus "proactive." I think we all agree a proactive solution to software security is most effective from a cost perspective. We also know from experience that external pressure is sometimes necessary to cause change. To put a slightly finer point on it, I wonder whether the "scatter" you can observe outside of the black box looks completely different than the in-the-box view. In this case, an organizations codebase and dev shop is "the box" and the external bug reports are outside. I have a feeling that is it. Trento has a special place in my heart as I lived there from 8/93-8/94 and worked at IRST. Say hi to Cognola for me. gem http://www.cigital.com/~gem On 3/19/09 4:42 AM, "Stephan Neuhaus" <Stephan.Neuhaus at disi.unitn.it> wrote: On Mar 18, 2009, at 23:14, Steven M. Christey wrote:
I believe this is reflected in public CVE data. Take a look at the bugs that are being reported for, say, Microsoft or major Linux vendors or most any product with a long history, and their current number 1's are not the same as the number 1's of the past.
I am trying to get funding for a study that would address precisely this issue. Here is a write-up that I made for the Master students here at the University of Trento that explains in more detail what I'm trying to do; perhaps someone on this list is interested in collaborating: http://www.disi.unitn.it/~neuhaus/proposals/Security-Trends.pdf Best, Stephan
Current thread:
- BSIMM: Confessions of a Software Security Alchemist (informIT) Gary McGraw (Mar 18)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Steven M. Christey (Mar 18)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Gary McGraw (Mar 18)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Steven M. Christey (Mar 18)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Gary McGraw (Mar 18)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Steven M. Christey (Mar 18)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Stephan Neuhaus (Mar 19)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Gary McGraw (Mar 19)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Stephan Neuhaus (Mar 19)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Gary McGraw (Mar 18)
- BSIMM: Confessions of a Software Security Alchemist (informIT) John Steven (Mar 19)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Gary McGraw (Mar 19)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Jim Manico (Mar 19)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Gary McGraw (Mar 19)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Benjamin Tomhave (Mar 19)
- BSIMM: Confessions of a Software Security Alchemist (informIT) kowsik (Mar 19)
- BSIMM: Confessions of a Software Security Alchemist(informIT) Goertzel, Karen [USA] (Mar 20)
- BSIMM: Confessions of a Software Security Alchemist(informIT) Benjamin Tomhave (Mar 20)
- Message not available
- BSIMM: Confessions of a Software Security Alchemist(informIT) Benjamin Tomhave (Mar 20)
- BSIMM: Confessions of a Software Security Alchemist (informIT) Steven M. Christey (Mar 18)
