expand icon
book Security in Computing 5th Edition by Shari Lawrence Pfleeger, Charles P Pfleeger, Jonathan Margulies cover

Security in Computing 5th Edition by Shari Lawrence Pfleeger, Charles P Pfleeger, Jonathan Margulies

Edition 5ISBN: 0134085043
book Security in Computing 5th Edition by Shari Lawrence Pfleeger, Charles P Pfleeger, Jonathan Margulies cover

Security in Computing 5th Edition by Shari Lawrence Pfleeger, Charles P Pfleeger, Jonathan Margulies

Edition 5ISBN: 0134085043
Exercise 1

List the issues involved in the software vulnerability reporting argument. What are the technical issues? What are the psychological/sociological ones? What are the managerial ones? What are the economic ones? What are the ethical ones? Select a vulnerability reporting process that you think is appropriate and explain why it meets more requirements than any other process.

Step-by-step solution
Verified
like image
like image

Step 1 of 8

Software vulnerability reporting

Software vulnerabilities are gateways that allow threats to manifest and affect a system. This allows the system to be compromised due to a weakness within the software. A vulnerability assessment searches for these weaknesses to remedy the issues arising out of them.

The issues involved in software vulnerability reporting are the following:

Plausible Denial – Most vulnerability are exploited after initial test attacks, which test the weakness of the system. Some vendors argue that full disclosure of vulnerability creates more potent variants, which may affect the system more.

Vendor Interests – A vendor usually finds it more feasible to offer security patches as a bundle, as opposed to provide a patch for each flaw as it is discovered. The problem with this approach is that while each vulnerability fix will be resource consuming and expensive, a bundle allows a weakness to remain for a longer period.

User Interests – Users generally are the biggest victims of unresolved weaknesses in a system. Since the vendor’s method of developing the bundle and installing patches leaves the system vulnerable, many security experts now support the view to publicize the existence of a weakness as soon as possible. This approach allows the attackers to isolate and attack a flaw until a patch is provided.


Step 2 of 8


Step 3 of 8


Step 4 of 8


Step 5 of 8


Step 6 of 8


Step 7 of 8


Step 8 of 8

close menu
Security in Computing 5th Edition by Shari Lawrence Pfleeger, Charles P Pfleeger, Jonathan Margulies
cross icon