Re: Experiences with company nCircle and their IP360 product

From: Tom Stracener (strace_at_gmail.com)
Date: 11/25/05

  • Next message: Joachim Schipper: "Re: Password cracking / recovery Lotus Notes R6"
    Date: Fri, 25 Nov 2005 16:10:14 -0600
    To: "Bongers, Coen" <coen.bongers@logicacmg.com>
    
    

    Coen,

    On the issue of unique or distinguishing features I would comment on
    nCircle's quantitative risk metrics for vulnerabilities. I created the
    formulas for this system back in 1999, and worked with other founding
    members to further refine and enhance the system over the next couple
    of years. Since then nCircle has continued to make modifications and
    improvements to the core risk analysis algorithms, and the result has
    been the development of a highly scalable risk analysis metric that
    allows you to view the risk of vulnerabilities, hosts, and networks at
    a glance.

    To help you understand the technical premises of vulnerability
    metrics, you can think of a vulnerability as having a penetration
    depth, to what degree does a successful attack correlate with elevated
    privileges. A sophistication factor, how difficult is it to exploit
    the vulnerability, what types of exploits, tools, worms, or exploit
    frameworks exist for the issue. An attack vector, how is the
    vulnerability exploited. Also, what is the vulnerability life-cycle
    state in relation to time. In essence, vulnerability risk is sort of
    parabolic over time, although with the delayed rate of patching and
    long-term persistence of vulnerabilities, the curve is less parabolic
    than you would think.

    These are just a few of the important assumptions. The importance or
    critically of the system on which a vulnerability is resident, the
    relation of the vulnerability to the network perimeter, etc., are also
    key factors. This should give you an idea of the advantage of using
    quantitative metrics in risk analysis, because you get a weighted
    generalization of all these factors with the benefit of granularity
    and succinct mathematical expression. High scoring systems and
    networks can then get your first attention, a significant advancement
    over having lists of thousands of low/medium/high qualitative labels.

    I don't know the extent to which IP360 still uses the factors above,
    but if you have an opportunity to view its output and reporting, know
    that the vulnerability and network scoring metrics were not technical
    wingdings tacked on at the behest of marketing -- but core technical
    features that have undergone years of serious scrutiny and refinement.

    Mike Murray has also done some amazing work on vulnerability signature
    precision. Be sure to check it out:

    http://www.ncircle.com/pdf/papers/nCircle_Precision_Metrics.pdf

    Hope my comments interest you.

    -Tom

    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner:

    Hackers are concentrating their efforts on attacking applications on your
    website. Up to 75% of cyber attacks are launched on shopping carts, forms,
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
    futile against web application hacking. Check your website for vulnerabilities
    to SQL injection, Cross site scripting and other web attacks before hackers do!
    Download Trial at:

    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------


  • Next message: Joachim Schipper: "Re: Password cracking / recovery Lotus Notes R6"

    Relevant Pages

    • Re: Risk metrics
      ... We have updated this in OSSTMM 3.0. ... The OSSTMM has pulled out of RISK completely because it is so biased ... New metrics are quantification-based-- facts only from operations used ... > Vulnerability scans and pen tests are a snapshot. ...
      (Pen-Test)
    • Re: vulnerability scanners not effective? or just a false-positive?
      ... I would not even classify them as a vulnerability. ... of an attack vector or a link in an attack tree, ... depends on the method used to determine risk. ... You have an option to go with a managed service or an enterprise software. ...
      (Pen-Test)
    • Re: Risk Ranking...
      ... get his book The Tao of Network Security Monitoring. ... I had the same problem as you when I was trying to come up with some risk ... The vulnerability must be exploited locally. ... If a piece of malware is a blended threat (able to exploit multiple ...
      (Security-Basics)
    • Re: Risk metrics
      ... security management life cycle. ... more objective snapshot of a company's risk posture. ... > traditional risk metrics in pen-tests cannot be ... >> vulnerability works, and if an exploit is in the ...
      (Pen-Test)
    • Re: Spyware and RISC OS? Surely not?
      ... complacency might be placing you at increased risk. ... You have more than one bank account with more than one ... and appropriate to the vulnerability of the situation. ...
      (comp.sys.acorn.misc)