3 ms·
Do we? The vast majority of our computing infrastructure is not actively and forensicly monitored; vulns are either actively patched out, accidently patched ou
by Normal_gaussian 5y ago
Do we?
The vast majority of our computing infrastructure is not actively and forensicly monitored; vulns are either actively patched out, accidently patched out, or 'reset' when services/servers are rolled (often due to "misbehaviour", be it a desktop by a user or a server by a tech), leaving no trace that they were exploited. The vast majority of vendors and sysadmins are incentivised not to reveal that they had an exploit, often by reclassification (exploit -> bug), failure to inform, or refusal to detect.
I think this is what the parent meant by "I'd assert that a good fraction of exploits are never caught/analyzed.".
Afaict as an outsider we account for this with honeypots, which should give us some kind of estimation at least.
- genewitch 5y agoWhat sorts of honeypots are available these days? In 2018 I wandered into honeypots again and windows was the primary host OS for most of them. That's not necessarily and issue, but the rest seemed abandoned or unfinished. On our subnet I was seeing a couple thousand cve exploits a month, and about the same in "unknown probes" that may or may not have been 0-days. I don't have (or want) access to the entire flows through the main gateway, but setting up a few honeypots with public IP is fine by me.