Sei sulla pagina 1di 100

How did we get here, knowing what we know?

Why Vulnerability Stats Suck


Stats are presented without understanding the limits of the data Even if explanations are provided, correlation is confused with causation:

Collect all the Vulns


98,012 vulnerabilities 65,878 products 9,183 vendors 6,459 researchers 111 years spanning from disclosed by over
@OSVDB

Circa 1973

Those

who cannot remember the past are condemned to repeat it. -- George Santayana

1960s

Pre-history (but relevant)

1950s

1930s

1900s

.-. .- - ... .-. .- - ... .-. .- - ... .-. .- - ... .-. .- - ...

Lessons Learned

Questions?

Thanks: Mar for awesome graphics OSF and RBS for providing resources to do the research Towne/Nickerson/Hutton for inspiration to tell a story Countless people that were around back then to give me info, pointers, and perspective You! For listening.

Potrebbero piacerti anche