3 ms·
An "0-day" is generally any "non-public" vulnerability. Any "0-day attack" is an any attack that uses an 0-day. If only the security researcher and vendor know
by jjguy 16y ago
An "0-day" is generally any "non-public" vulnerability. Any "0-day attack" is an any attack that uses an 0-day. If only the security researcher and vendor know of the vulnerability details, it is still an 0-day. Once the vendor releases a patch, bindiff will (usually) point very rapidly to the root cause. Thus, the details are considered public, regardless of previous disclosure details.
These capture the imagination and frustrate system administrators because 0-day -- due to their unknown nature and nearly infinite possibility -- cannot be simply "fixed."
This has been a core frustration of mine in the network defense community for years: our procedures are too narrowly focused on protection -- keeping bad guys out. This is necessary but insufficient. We must assume bad guys will get in and focus on how we detect, respond and recover. Unfortunately, these last three steps get ignored too often -- resulting in bad guys never being detected once they're inside the gates.
- JoachimSchipper 16y agoYou seem to totally ignore historical data - i.e. you install software that had 300 vulnerabilities last year, then assume it will get hacked. Restricting yourself to software with, say, at most one vulnerability in the last five years helps a lot. (Yes, I know this can be "impractical". But then you deserve what you get.)