About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Sans Institute
Top 20 security threats
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Top 20 security flaws revealed

Patching could reduce viruses, spam and cyber-exortion, says Sans Institute

Daniel Thomas, Computing 11 Oct 2004
ADVERTISEMENT

Businesses, vendors and individual computer users could stop most viruses and cyber attacks spreading by fixing a small number of common technology flaws, according to research.

Viruses, spam and distributed denial of service attacks could all be reduced by patching a number of common vulnerabilities found in Windows and Unix systems, says the government-backed Sans Institute.

The study, which includes contributions from the UK's National Infrastructure Security Co-ordination Centre and the Cabinet Office's Central Sponsor for Information Assurance (CSIA) department, found instant messaging, internet browsers and web services were among the most common threats.

'Every day there are new vulnerabilities, new hacks and new exploits,' said CSIA director Stephen Marsh.

'Most people would use commercial off-the-shelf products if they were secure, and it is our job to make it easier.'

But Sans Institute Director, Alan Paller, told Computing that although companies needed to protect against the flaws, many of the related information security risks and costs could be removed if businesses put the onus on vendors to test systems before roll-out.

'The main thing to start thinking about right now is saying to your procurement department "We won't accept technologies with vulnerabilities",' said Paller.

Last month, Gartner also told Computing that businesses should put more pressure on vendors to remove security flaws before products are launched.

The analyst firm predicted that a 50 per cent reduction in software vulnerabilities before shipping could remove 75 per cent of configuration management and incident response costs incurred by businesses.

Top Vulnerabilities to Windows Systems

*Web Servers & Services

*Workstation Service

*Windows Remote Access Services

*Microsoft SQL Server (MSSQL)

*Windows Authentication

*Web Browsers

*File-Sharing Applications

*LSAS Exposures

*Mail Client

*Instant Messaging

Top Vulnerabilities to UNIX Systems

*BIND Domain Name System

*Web Server

*Authentication

*Version Control Systems

*Mail Transport Service

*Simple Network Management Protocol (SNMP)

*Open Secure Sockets Layer (SSL)

*Misconfiguration of Enterprise Services NIS/NFS

*Databases

*Kernel

What do you think? Email feedback@computing.co.uk

If you want to be first with the news, visit Computing every day.

See also:

Ten security patches'Critical' vulnerabilities could allow attackers to gain complete control  13 Oct 2004

All Chips & Components

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Shinfield Park, Reading, United Kingdom | Foster Wheeler
Our UK-headquartered operations employ more than 6,000 people and we are seeking qualified and experienced IT professionals to work in our head office in Reading, Berkshire. We are currently seeking an Analyst Programmer to join ... more >
London, United Kingdom | BP
 IT Leader -£ Competitive - London About BP Our business is the exploration, production, refining, trading and distribution of energy. This is what we do, and we do it on a truly global scale. With ... more >
Hertfordshire, United Kingdom | Tesco.com
Senior Business Analyst - Hertfordshire Who's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at just under ... more >
Central London, United Kingdom | MI5 Security Services
Domain Infrastructure Technician - Competitive + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to help ... more >
More job opportunities
ADVERTISEMENT