Windows of vulnerability: a case study analysis
Arbaugh, W.A.; Fithen, W.L.; McHugh, J.
Computer
Volume 33, Issue 12, Dec 2000 Page(s): 52 - 59
Digital Object Identifier 10.1109/2.889093
Summary: The authors propose a life cycle model for system vulnerabilities, then apply it to three case studies to reveal how systems often remain vulnerable long after security fixes are available. For each case, we provide background information about the vulnerability, such as how attackers exploited it and which systems were affected. We then tie the case to the life-cycle model by identifying the dates for each state within the model. Finally, we use a histogram of reported intrusions to show the life of the vulnerability, and we conclude with an analysis specific to the particular vulnerability.
View citation and abstract |