|
Number of security flaws nearer to 140,000 |
|
Monday, 04 June 2007 |
Most vulnerabilities in applications never see the light of day, according to security expert.
While the number of reported security vulnerabilities was around 7,200 last year, the actual figure could be as high as 140,000, according to an expert.
Gunter Ollmann, director of security strategy at IBM's security subsidiary ISS, said that while 7,247 flaws were publicly disclosed in 2006 and over 2,500 were discovered so far this year, many more will escape the attention of most of us.
Ollmann reckoned that 125,000 flaws per year never saw the light of day as they were found by penetration testers working under contract to organisations. These organisations then claimed ownership of vulnerabilities while working to fix the bugs.
He said he would estimate that an average consulting penetration tester would uncover five to ten new flaws per day when assessing applications. These were exploits found in web-based applications, competitive reviews of compiled business applications, custom deployment of mainstream applications, or even in-house developed software.
Source: http://www.itpro.co.uk/news/114420/number-of-security-flaws-nearer-to-140000.html
|