Advisories and relative security
Advisories and relative security
Posted Sep 4, 2003 8:40 UTC (Thu) by AnswerGuy (guest, #1256)Parent article: Advisories and relative security
The metrics here aren't reasonable. When I did software quality assurance
we eschewed the usual categorization of bugs (cat. 1 through cat. 4) for
a three dimensional rating system: virulence, severity, embarassment.
I won't go into details on that; but consider this: In the last 5 years
there have been 3 Linux worms that I can remember: Lion, Ramen, and Adore.
All three of them combined affected perhaps a few 10's of thousands of
systems (and almost all of them a few years ago).
In the last 2 years I can think of Nimda, Code Red, MS-Sapphire (SQL
Slammer), and MS-Blaster the smallest of which affected hundreds of
thousands of systems. The SoBig and other viruses are almost one order
of magnitude more virulent than the worms.
So, when we evaluate the costs and risks based the number of affected
systems and the severity of the compromises --- we see that UNIX and
Linux are a better bet.
