<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Oh No! Security Metrics!</title><link>http://blogs.msdn.com/b/sdl/archive/2008/04/18/oh-no-security-metrics.aspx</link><description>Hello, Michael here. 
 A colleague sent me a link to a blog post from a couple of days ago: Pete Lindstrom of Burton Group blogged that Microsoft's SDL has Saved the World!! raising concerns about Microsoft using vulnerability counts as a means to measure</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>How Secure is Secure?</title><link>http://blogs.msdn.com/b/sdl/archive/2008/04/18/oh-no-security-metrics.aspx#8472809</link><pubDate>Thu, 08 May 2008 19:47:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8472809</guid><dc:creator>The Security Development Lifecycle</dc:creator><description>&lt;p&gt;Hi folks, Eric Bidstrup here. As I touched on in my December posting on Common Criteria , and as Michael&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8472809" width="1" height="1"&gt;</description></item><item><title>re: Oh No! Security Metrics!</title><link>http://blogs.msdn.com/b/sdl/archive/2008/04/18/oh-no-security-metrics.aspx#8435832</link><pubDate>Mon, 28 Apr 2008 21:07:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8435832</guid><dc:creator>SDL Team</dc:creator><description>&lt;p&gt;Bryan&lt;/p&gt;
&lt;p&gt;We do measure attack surface, it's a critical part of a product's security and one facet of the SDL that has nothing to do with code security. In general, we've driven the attack surface down substantially from Win2000 and Windows XP. The good news is you can decide on your metrics and measure it for yourself :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8435832" width="1" height="1"&gt;</description></item><item><title>re: Oh No! Security Metrics!</title><link>http://blogs.msdn.com/b/sdl/archive/2008/04/18/oh-no-security-metrics.aspx#8423896</link><pubDate>Fri, 25 Apr 2008 14:23:28 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8423896</guid><dc:creator>bryansowen</dc:creator><description>&lt;p&gt;Perhaps a review of relative attack surface quotient would offer insight about the effectiveness of early SDL stages. &lt;/p&gt;
&lt;p&gt;Specifically include Windows 2008 and Server Core to the charts from 2003 &amp;quot;Measuring Relative Attack Surfaces&amp;quot; by Howard, Pincus, Wing.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8423896" width="1" height="1"&gt;</description></item><item><title>re: Oh No! Security Metrics!</title><link>http://blogs.msdn.com/b/sdl/archive/2008/04/18/oh-no-security-metrics.aspx#8414723</link><pubDate>Mon, 21 Apr 2008 17:39:50 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8414723</guid><dc:creator>Patrick_Boyd</dc:creator><description>&lt;p&gt;I really wouldn't worry about Mr. Lindstrom's criticism very much. &lt;/p&gt;
&lt;p&gt;Are publicly disclosed vulnerability count a perfect metric of security? Of course not. &lt;/p&gt;
&lt;p&gt;But is it the best metric that we currently have access to? I think so, and obviously Microsoft does too.&lt;/p&gt;
&lt;p&gt;Until Mr. Lindstrom can suggest a better metric, or someone else can. I would stay the course and keep doing your best to secure the OS and tools that most of us run.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8414723" width="1" height="1"&gt;</description></item><item><title>re: Oh No! Security Metrics!</title><link>http://blogs.msdn.com/b/sdl/archive/2008/04/18/oh-no-security-metrics.aspx#8408116</link><pubDate>Fri, 18 Apr 2008 18:44:01 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8408116</guid><dc:creator>asteingruebl</dc:creator><description>&lt;p&gt;Michael,&lt;/p&gt;
&lt;p&gt;To the outsider however its not clear where the defect reduction is coming from. &amp;nbsp;What we'd love to have some insight into is whether you're measuring defects at multiple stages of the development lifecycle and seeing reductions throughout.&lt;/p&gt;
&lt;p&gt;Part of this goes to the question of efficiency. &amp;nbsp;You could for example simply test the hell out of things, hire better testers, etc. &amp;nbsp;If you didn't do developer education, didn't do threat modeling, and still got a massive reduction in the end vulnerability count, you'd still have an effective process and it would show up in fewer patches. &lt;/p&gt;
&lt;p&gt;If you don't have any metrics about the effectiveness of training, threat modeling, etc. and you can't track where defects are being created, and discovered/prevented, then its hard to know which parts of the process are working and which aren't. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;This isn't to say that MS needs to share all of its internal metrics, tracking, etc. &amp;nbsp;But, it does point to vuln counts as not at all indicating that the SDL is working, but maybe that some part of it is working. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;I think you're positioned to pull together some very interesting metrics because of your diversity. &amp;nbsp;Things like defect counts of a given type per programming language and/or dev environment. &amp;nbsp;Details on the percentage of design vs. implementation defects, and when they are being discovered. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Do you have anyone sitting around doing nothing who wants to just work on publishing metrics and such for the rest of us to consume? :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8408116" width="1" height="1"&gt;</description></item><item><title>Oh No! Security Metrics!</title><link>http://blogs.msdn.com/b/sdl/archive/2008/04/18/oh-no-security-metrics.aspx#8408074</link><pubDate>Fri, 18 Apr 2008 18:35:02 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8408074</guid><dc:creator>Michael Howard's Web Log</dc:creator><description>&lt;p&gt;I just posted an article over on the SDL blog about security metrics in reponse to an analysts criticisms&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8408074" width="1" height="1"&gt;</description></item></channel></rss>