Vulnerability management strategy, from both organizational and public policy perspectives, hinges on an understanding of the supply of undiscovered vulnerabilities. If the number of undiscovered vulnerabilities is small enough, then a reasonable investment strategy would be to focus on finding and removing the remaining undiscovered vulnerabilities. If the number of undiscovered vulnerabilities is and will continue to be large, then a better investment strategy would be to focus on quick patch dissemination and engineering resilient systems. This paper examines a paradigm, namely that the number of undiscovered vulnerabilities is manageably small, through the lens of mathematical concepts from the theory of computing. From this perspective, we find little support for the paradigm of limited undiscovered vulnerabilities. We then briefly support the notion that these theory-based conclusions are relevant to practical computers in use today. We find no reason to believe undiscovered vulnerabilities are not essentially unlimited in practice and we examine the possible economic impacts should this be the case. Based on our analysis, we recommend vulnerability management strategy adopts an approach favoring quick patch dissemination and engineering resilient systems, while continuing good software engineering practices to reduce (but never eliminate) vulnerabilities in information systems.
翻译:漏洞管理策略,无论是从组织角度还是公共政策角度,都取决于对未发现漏洞供应情况的理解。若未发现漏洞数量足够少,则合理的投资策略应聚焦于发现并消除剩余未发现漏洞;若未发现漏洞数量当前及未来持续较大,则更优的投资策略应侧重于快速补丁分发与弹性系统设计。本文通过计算理论中的数学概念视角,审视了"未发现漏洞数量可管理性地保持少量"这一范式。基于此视角,我们未发现支持"有限未发现漏洞"范式的充分依据。我们进一步论证了这些理论结论与当今实用计算机系统的相关性。研究未发现任何理由认为实践中未发现漏洞本质上不是无限的,并探讨了此情形下可能产生的经济影响。基于分析,我们建议漏洞管理策略采纳侧重快速补丁分发与弹性系统设计的方法,同时持续执行良好的软件工程实践以减少(但无法消除)信息系统中的漏洞。