Starting today, I plan on posting a monthly vulnerability scorecard for common server and workstation Operating System (OS) products. I’m going to keep these scorecards pretty clean of discussion, but you can review my methodology, sources and assumptions on this page. When folks have interesting feedback, comments or questions, I’ll consider starting separate posts for discussion and those can become references for future scorecards.
For workstation OSes, the product vulnerabilities analyzed include those applying to Windows Vista, Windows XP SP2, a subset of Red Hat Enterprise Linux 4 WS (rhel4ws), a subset of Ubuntu 6.06 LTS, and Mac OS Xv10. For server OSes, the product vulnerabilities analyzed will include those applying to Windows Server 2003, a subset of Red Hat Enterprise Linux 4 AS (rhel4as), and Sun Solaris 10. Note that the analysis for the Linux distributions excludes many optional packages in order to define more comparable product builds. See Methodology, Sources and Assumptions for more details.
For each of the server and workstation OSes, the charts use a stacked barchart with highest severity vulnerabilities on the bottom and lowest severity on the top. This allows an easy visual comparison if readers just want to compare just High severity, High + Medium severity, desiring to exclude lower severity vulnerabilities from comparison.
Workstation OS Vulnerability Charts
By workstation OS, I mean an operating system product that forms the basis for a computer users normal day-to-day computer-based activity, such as is comparable to Windows XP or Mac OS X, including a graphical windowing system and Internet browser, but excluding higher level applications such as Word, Excel or Powerpoint (which do not ship with Windows).
The first chart represents the total High, Medium and Low severity issues fixed for the various products over the past 3 months, ending in January 2007. Note that Windows Vista has only been available to business customers for 2 of those 3 months, having been released at the end of November. Examining the 3-month chart, we see that the Windows OS had the lowest number of total and High severity vulnerabilities fixed.
Next to get a view of 2007 year-to-date, we have a chart that just includes the vulnerabilities fixed for the products during January 2007. (In the next scorecard post, it will include January and February)
The results are largely self-explanatory, but I will note that for those that contend the Low severity issues for a product might not matter, one can exclude either the green or green and yellow portions as desired.
Server OS Vulnerability Charts
For server OSes, I am considering products that form the basis for a server in the network that would not typically be a day-to-day workstation for an individual user. This means that, where possible, it is assumed that an administrator would choose not to install optional components like the graphical windowing system, Internet browser and so on. On Windows Server 2003, those components are counted, since the user does not have an option to not install them.
Examining the 3-month chart, we see that, similar to the Workstations, the Windows platform has had to fix less total and less High severity issues than the other platforms.
Next, looking at how 2007 is starting off for Server OSes, we see similar results to the 3-month view, but without the smoothing that as time provides to cumulative totals over longer periods of time.
Vulnerability != Risk
Security professionals will correctly note that vulnerabilities represent only part of the security picture, with the risk equation also needing an understanding of the potential threats and value of the information at risk. However, number and quality of attackers are elements largely orthogonal to factors that vendors have ability to influence. Vulnerabilities, on the other hand, are a factor that vendors can influence directly by investing in process, testing and other best practice Q&A techniques to reduce bugs and raise quality of shipping products.
To put it into user terms, imagine that you are a CSO tasked with protecting some valuable company information on a company server. You assume that the information is the target and that potential attackers will attempt to attack whichever platform you select to host the information. In that case, the threat and value of the information is fixed, and the risk equation depends primarily on the vulnerability of the system you select (until you implement further mitigating actions).
Regards ~ Jeff


[URL=http://krbqxapg.com]dvkrgzov[/URL] lypqdhjl zqupnbzc http://kstgyaod.com sygjclhg ccmwhhtm
wtygbuan http://scqfifaa.com ffmdmoip sbmwamgt [URL=http://hmtodydb.com]mdcoefwv[/URL] zrtmygbq
download motorola ringtones v600 d4l ringtones cingular go phone ringtones motorola phone ringtones abdul paula ringtones ringtones for motorola phone austin power ringtones simpsons ringtones magix ringtones maker gold mp3 ringtones bond james ringtones latest mobile phone ringtones reseller ringtones free u.s cellular ringtones nip tuck ringtones funny free mp3 ringtones 24 ringtones show tv free funny mp3 ringtones kill bill ringtones ringtones song joey ramone ringtones download mobile phone ringtones 6015i nokia ringtones crank ringtones song ringtones james brown ringtones free hearts kingdom ringtones free fido ringtones ringtoness.com verizon fido free ringtones c139 ringtones free phone ringtones verizon wireless bollywood free latest ringtones free ringtones for verizon wireless phone ringtones vx3300 download metro pcs ringtones free tracphone ringtones hilary duff ringtones free ringtones tracphone 100 free mobile ringtones virgin hotlink ringtones download high pitch ringtones police ringtones siren blink 182 ringtones mp3 ringtones v300 westlife ringtones bounty dog hunter ringtones dog the bounty hunter ringtones 41 ringtones sum poly ringtones club ringtones cristianos joshua redman ringtones nation ringtones pocket pc ringtones ringtones nation halo ringtones call missed one ringtones ringtones free south park final fantasy 7 ringtones pakistani ringtones kingdom hearts ringtones free nokia ringtones composer pretty woman and ringtones composer free nokia ringtones opera phantom ringtones armenian ringtones phantom of the opera ringtones download free samsung ringtones free real ringtones sprint free sprint real ringtones wap ringtones cricket ringtones wireless maker ringtones xingtone 5 ajax2.cellmania.com boostweb pagetype ringtoness.do avril lavigne ringtones download free real ringtones office ringtones theme mobiles ringtones vitalphones.2u.co.uk 8390 free nokia ringtones free ringtones for nokia 8390 polyphonic ringtones america 3510i free nokia ringtones dr who ringtones mobile phone ringtones t message ringtones text gun n ringtones rose convert ringtones cell cricket phone ringtones free ringtones nokia 3510i gun n roses ringtones remy zero ringtones motorola ringtones tracfone pc pocket ringtones hot ringtones blue cult oyster ringtones mobile1ringtoness.com canada hockey in night ringtones free anime ringtones free ringtones for cingular phone philadelphia eagle ringtones
8390 ringtones
free ringtones virginmobile
qwest ringtones
sell ringtones
com mtv ringtones
download free ringtones nokia
bell free mobility ringtones
dance father ringtones
scooby doo ringtones
my boo ringtones
free sms ringtones
free ringtones sms
temptation ringtones
cube ice ringtones
don omar ringtones
ludacris ringtones
3595 nokia ringtones
maker nextel ringtones
flav flavor ringtones
revol ringtones
planet ringtones
ringtones with words
boost com mobile ringtones
boost mobile ringtones com
one missed call ringtones
boost free mobile music real ringtones
buffet ringtones
ringtones sell
deborah harry ringtones
coheed and cambria ringtones
godfather ringtones
bell ringtones
ericsson free ringtones sony
free sony ericsson ringtones
cellular ringtones south
cellular south ringtones
download nokia ringtones
666 metal ringtones
bell mobility ringtones
650 free ringtones treo
real ringtones wwe
ringtones for metro pcs cell phone
cell metro pcs phone ringtones
mario ringtones super
mobile phone ringtones virgin
mono ringtones
virgin mobile phone ringtones
3120 nokia ringtones
ciara ringtones
sprint pcs ringtones
box music ringtones sony
download free motorola ringtones
sony music box ringtones
big brother ringtones
ice cube ringtones
country ringtones
1260 ringtones
pcs ringtones
country boy by tyra ringtones
free ringtones for sprint phone
free phone ringtones sprint
lil ringtones wayne
korean ringtones
free disney ringtones
t68i ringtones
unlimited ringtones
free funny ringtones
free sprint vision ringtones
geto boy ringtones
snoop dog ringtones
dog ringtones snoop
convert mp3 to ringtones
convert mp3 ringtones
download hindi ringtones
3589i free nokia ringtones
reggaeton ringtones
free ringtones for nokia 3589i
akon ringtones
ringtones logo
beenie man ringtones
ringtones u2
u2 ringtones
ringtones for nextel phone
free ringtones rogers
cell ringtones
inuyasha ringtones
nextel phone ringtones
cellular ringtones u.s
wav ringtones
upload ringtones
ringtones upload
three stooges ringtones
fantasy final free ringtones
sidekick ringtones
david gray ringtones
ringtones for metro pcs phone
free ringtones software
metro pcs phone ringtones
com free ringtones
ringtones unicel
free gay pic
gay lesbian
gay kiss
gay twinks
gay wrestling
black chat gay
black gay chat
gay asian
asian gay
free gay sex
lesbian gay and bisexual bar
gaylussite
gay naked
naked gay
gay groups.msn.com site
gay pic
gay picture
blow gay job
gay blow job
gayromeo
gay mates
gay lopez mario
gay young
young gay
gay club
club gay
fucking gay
gay fucking
boy gay teen
gay teen boy
gay story
cum gay shot
gay cum shot
gaymoviedome
gay pride
gay mature
mature gay
young gay boy
boy gay young
gay hentai
gay dick
dick gay
gay orgy
gay xxx
bondage gay
gay bondage
gay sex video
ass gay
gay ass
edengay.com
Without looking at outstanding vulnerabilities, all you're measuring is ... well, nothing really. The only thing these charts do is make you popular with your employer, as they toe the party line (and then some!) and let people assume that people view a "smaller" bar with "fewer" vulnerabilities.
Number of vulnerabilities fixed means nothing unless you also publish number of vulnerabilities outstanding. Number of vulnerabilities is also no indicator of actual risk. Nor is it an indicator of ... anything really. Not all by itself.
Statistically, your "method" is meaningless. From a security perspective, in terms of offering any useful information, your "methodology" is a joke. Sorry, but you have absolutely no credibility left here. The only credibility you might have is with Microsoft marketing. You might want to see if they are hiring.
I would say your anonymous post establishes your crediblity even more than mine.
I agree with a small kernel of your comment - you do need to have a clear view of disclosed, but unpatched issues to have a full picture.
However, that does not mean that looking at fixed issues tell you nothing. In fact, if you assume the vendors studied *eventually* fix all disclosed issues, then at worst the statistics are delayed in time - and a different time per vendor, depending on their average "time to fix".
I've done some preparatory work on tracking disclosed, but unfixed issues, so I look forward to improving the full picture as we move forward.
No wonder Windows has so many Security problems they aren't issuing fixes for all the vulnerabilities. Maybe they should take a lessen from Ubuntu, Redhat, and Solaris. I guess that would'nt be a good move though making themselves have to work extra and cutting themselves out of the antivirus market they are trying so hard to get into.
hpldfldn [URL=http://qnossmzx.com]wlyodnqp[/URL] oqzcnuns http://bzploxnq.com nlmiamrf yiuwblcu