• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Why Surging Security Vulnerability Rate May Be a Good Thing

    September 7, 2010 Alex Woodie

    The number of security vulnerabilities discovered in the first six months of 2010 increased by 36 percent compared to 2009, according to IBM‘s X-Force security team, which recently released its Mid-Year Trend and Risk Report. More than half of these vulnerabilities–mostly problems with Web applications–were still unpatched as July began. That’s the bad news. The good news is that vulnerability disclosures are increasing, which means vendors are getting the transparency message.

    The X-Force Research and Development team documented 4,396 new vulnerabilities in the first half of 2010, and 55 percent of these vulnerabilities had no vendor-supplied patch at the end of the period, the X-Force says. The complexity of Web apps developed with JavaScript, the darling of Web 2.0, continues to be a big problem, as is Adobe‘s Portable Document Format. Cloud computing and virtualization products are just starting to pop up on the long-range X-Force radar.

    The increase in vulnerability rates is a reversal from previous trends. In 2008 and 2009, IBM and Microsoft reported declining vulnerability rates. That seemed to indicate that vendors were getting a handle on their production processes, that technologies were maturing, and that the World Wide Web was becoming a safer place to browse.

    But IBM X-Force seems to indicate that it’s not such a bad thing that that the vulnerability rate is going up. This may seem counterintuitive at first. After all, hackers and cyber-criminals are actively exploiting these vulnerabilities to steal fortunes from victims all over the world. Wouldn’t fewer vulnerabilities mean less opportunity for criminals?

    The answer is, yes and no. Security professionals recognize that total security can never be achieved. Instead, one can only hope to contain the problem by implementing processes that seek to minimize the scope of the software problems and the attackable surface on which cyber-criminals feed. Without a huge breakthrough that suddenly allows programmers to write cleaner code with less effort (and that is definitely NOT happening with Web 2.0 technologies), one can assume that new flaws in software code will be introduced at a relatively constant rate.

    Without a way to break this unavoidable baseline of new vulnerabilities, the best way to deal with the problem is to accelerate the remediation process, which involves getting vendors to publicly acknowledge they have a problem more quickly, and get their own developers and the open source community working on a solution.

    This is what IBM says is happening, and that is a good thing. “This year’s X-Force report reveals that although threats are on the rise, the industry as a whole is getting much more vigilant about reporting vulnerabilities,” states Steve Robinson, general manager of IBM Security Solutions, in a press release. “This underscores the increased focus among our clients to continue looking for security solutions that help them better manage risk and ensure their IT infrastructure is secure by design.”

    RELATED STORIES

    Hackers Escalate Web Site Attacks, Despite Decline in Security Vulnerabilities

    Web Site Vulnerabilities Continue Unabated, IBM X-Force Says

    Decline In Vulnerabilities Belies Threat Increase, Microsoft Says in New Security Report

    Surf’s Up for Web-Based Organized Crime, IBM X-Force Says



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    DRV Tech

    Get More Out of Your IBM i

    With soaring costs, operational data is more critical than ever. IBM shops need faster, easier ways to distribute IBM applications-based data to users more efficiently, no matter where they are.

    The Problem:

    For Users, IBM Data Can Be Difficult to Get To

    IBM Applications generate reports as spooled files, originally designed to be printed. Often those reports are packed together with so much data it makes them difficult to read. Add to that hardcopy is a pain to distribute. User-friendly formats like Excel and PDF are better, offering sorting, searching, and easy portability but getting IBM reports into these formats can be tricky without the right tools.

    The Solution:

    IBM i Reports can easily be converted to easy to read and share formats like Excel and PDF and Delivered by Email

    Converting IBM i, iSeries, and AS400 reports into Excel and PDF is now a lot easier with SpoolFlex software by DRV Tech.  If you or your users are still doing this manually, think how much time is wasted dragging and reformatting to make a report readable. How much time would be saved if they were automatically formatted correctly and delivered to one or multiple recipients.

    SpoolFlex converts spooled files to Excel and PDF, automatically emailing them, and saving copies to network shared folders. SpoolFlex converts complex reports to Excel, removing unwanted headers, splitting large reports out for individual recipients, and delivering to users whether they are at the office or working from home.

    Watch our 2-minute video and see DRV’s powerful SpoolFlex software can solve your file conversion challenges.

    Watch Video

    DRV Tech

    www.drvtech.com

    866.378.3366

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    PowerTech:  FREE Webinar! Protect IBM i Data from FTP, ODBC, & Remote Command. Sept 15, 10 am CT
    looksoftware:  RPG OA & Beyond Webinar. Sept 28 & 29. Enter to win an Amazon Kindle™
    COMMON:  Join us at the Fall 2010 Conference & Expo, Oct. 4 - 6, in San Antonio, Texas

    IT Jungle Store Top Book Picks

    Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
    The iSeries Express Web Implementer's Guide: List Price, $49.95
    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    Chip Wars: List Price, $29.95

    Admin Alert: One Year Out–Preparing for Your Next Power IBM i Upgrade Get Thee to the Web, Part 1

    Leave a Reply Cancel reply

Volume 10, Number 31 -- September 7, 2010
THIS ISSUE SPONSORED BY:

ProData Computer Services
Bytware
RevSoft
ManageEngine
RJS Software Systems

Table of Contents

  • MKS Offers Full Support for IBM i 7.1 in ALM Tool
  • Vanguard Adds Graphical Workflow Features to IBM i Imaging Solution
  • Valid and TGS Gang Up on Buddy Punchers
  • Quantum Adds Fibre Channel to Midrange De-dupe Boxes
  • CCSS Cracks Down on IBM i Jobs with Excessive I/O
  • PowerTech to Overhaul Free IBM i Security Policy Template
  • Wavelink Finds Another Use for Smartphones
  • BackOffice Unveils Cloud-Based Data Migration Tool
  • IBM Moves Rational Cafes to New Website
  • Why Surging Security Vulnerability Rate May Be a Good Thing

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • The Power11 Transistor Count Discrepancies Explained – Sort Of
  • Is Your IBM i HA/DR Actually Tested – Or Just Installed?
  • Big Blue Delivers IBM i Customer Requests In ACS Update
  • New DbToo SDK Hooks RPG And Db2 For i To External Services
  • IBM i PTF Guide, Volume 27, Number 33
  • Tool Aims To Streamline Git Integration For Old School IBM i Devs
  • IBM To Add Full System Replication And FlashCopy To PowerHA
  • Guru: Decoding Base64 ASCII
  • The Price Tweaking Continues For Power Systems
  • IBM i PTF Guide, Volume 27, Numbers 31 And 32

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle