Twitter Facebook Google RSS
 
Security Beat 

Governments Should Push Vendors to Eliminate Software Security Flaws, Researchers Say 

2,011 

By Stew Magnuson 

Security incidents in cyberspace can be prevented if governments push the creators of operating systems to test their software more thoroughly before releasing their products, two of the United Kingdom’s leading authorities on computer security said.

Patches sent out by vendors after the release of an operating system have become the norm, but they suggest that the software has not been properly vetted, said Peter Sommer and Ian Brown in a report, “Reducing System Cybersecurity Risk,” produced by the Organization for Economic Cooperation and Development, a 34-member intra-governmental organization headquartered in Paris.

“Large numbers of attack methods are based on faults discovered in leading operating systems and applications,” the authors said.

Governments should use their procurement power, standards setting and licensing to “influence industry suppliers to provide properly tested hardware and software,” they said.

The report is part of a series looking at “future global shocks.” Sommer and Brown downplayed the possibility of a large-scale cyberwar having a widespread impact on the world.

The term “cyber-attack” is often overhyped, they said, and has come to encompass even the most ham-handed phishing attempts to steal a password.

“Rolling all these activities into a single statistic leads to grossly misleading conclusions,” they said.

“It is unlikely that there will ever be a true cyberwar,” they said. Critical computer systems are protected against known threats, and finding unknown vulnerabilities that can be used in a global attack is difficult. In addition, the perpetrators know the unpredictability of a war means that they would be equally damaged.

There is one potential “shock” that is not often discussed: a massive solar flare could physically destroy key communication components such as satellites, cellular base stations and switches, they said.

Submit Your Reader's Comment Below
*Name
 
*eMail
 
The content of this field is kept private and will not be shown publicly.
*Comments
 
 
Refresh
Please enter the text displayed in the image.
The picture contains 6 characters.
*Characters
  
*Legal Notice

NDIA is not responsible for screening, policing, editing, or monitoring your or another user's postings and encourages all of its users to use reasonable discretion and caution in evaluating or reviewing any posting. Moreover, and except as provided below with respect to NDIA's right and ability to delete or remove a posting (or any part thereof), NDIA does not endorse, oppose, or edit any opinion or information provided by you or another user and does not make any representation with respect to, nor does it endorse the accuracy, completeness, timeliness, or reliability of any advice, opinion, statement, or other material displayed, uploaded, or distributed by you or any other user. Nevertheless, NDIA reserves the right to delete or take other action with respect to postings (or parts thereof) that NDIA believes in good faith violate this Legal Notice and/or are potentially harmful or unlawful. If you violate this Legal Notice, NDIA may, in its sole discretion, delete the unacceptable content from your posting, remove or delete the posting in its entirety, issue you a warning, and/or terminate your use of the NDIA site. Moreover, it is a policy of NDIA to take appropriate actions under the Digital Millennium Copyright Act and other applicable intellectual property laws. If you become aware of postings that violate these rules regarding acceptable behavior or content, you may contact NDIA at 703.522.1820.

 
 
  Bookmark and Share