200 likes | 809 Views
Vulnerability Management Lifecycle. Panel Discussion. Panelists. Carole Fennelly - Tenable Network Security Chris Wysopal - Veracode Steven Christey - MITRE Bob Martin - MITRE HD Moore - Rapid7 Jonathan Klein - Broadridge Financial Solutions
E N D
Vulnerability Management Lifecycle Panel Discussion
Panelists Carole Fennelly - Tenable Network Security Chris Wysopal - Veracode Steven Christey - MITRE Bob Martin - MITRE HD Moore - Rapid7 Jonathan Klein - Broadridge Financial Solutions Kelly Todd - OSVDB
Overview • Vulnerability Discovery • Private Vulnerability Sharing • Public Disclosure • Vulnerability Database Management • Vulnerability Monitoring/Testing • Remediation
Vulnerability Discovery • Monitoring for Anomalies/ 0-Day • Monitoring Local Applications • Initial Discovery of Vulnerability • Development of Exploit • Posting to security lists
Private Vulnerability Sharing • Passing around on underground lists • Additional research • Expanded impact • 0-day exploits • “Oops, I broke the Internet…”
Public Disclosure • Determine when to disclose • Coordination between vendor and researcher • What to disclose • Public reaction/ working with media • FUD
Vulnerability Database Management • Monitoring of sources • Validation • Summarization • Classification • Determine/develop remediation measures
Vulnerability Monitoring/Testing • Vulnerabilities discovered during a penetration test • Vulnerabilities discovered by security software (IDS, Logs, Scanners) • Vulnerabilities discovered from external source
Remediation • Analysis of organizational impact • Prioritization • Determine/test remediation measures
Questions? cfennelly@tenablesecurity.com coley@mitre.org ramartin@mitre.org cwysopal@gmail.com jonathan.klein@broadridge.com hdm@metasploit.com lyger@attrition.org