Case Study

Testing for Trouble

  • July/August 2010
  • By Erica Naone

Josh Abraham and Will Vandevanter are two of the experts who analyze security vulnerabilities for Rapid7.
Christopher Churchill

In the first two months of 2010 alone, 1,223 new vulnerabilities were added to the Open Source Vulnerability Database, a project designed to gather reports about security issues in all types of software. It's not unusual, then, for a company that relies on software to have thousands of vulnerabilities spread across various systems.

But there's a difference between a vulnerability and a real risk, says Corey Thomas, executive vice president of the Boston-based computer security firm Rapid7. If it's difficult for an attacker to exploit a vulnerability, Thomas says, then it doesn't amount to much of a threat.

Last year, Rapid7 acquired Meta­sploit, an open-source framework that tests systems for security holes, thus helping organizations separate threats from mere vulnerabilities. Metasploit's researchers and members of the open-source community use various strategies to stay on top of the vulnerabilities that attackers actually use, including watching news reports and monitoring systems designed to trap malware. The researchers can then create modules to see how systems would respond to an attack. Metasploit modules work the same way malicious software would, except that the user controls what the software does to the system after a breach is found. This lets users identify where they're at risk without suffering any damage.

Rapid7 maintains Metasploit as an entirely free, open-source project. It makes money by selling products that build on Metasploit or offering businesses additional services. But the very openness and easy availability of Metasploit modules suggest another problem. Rapid7 feared that acquiring Metasploit would cause a backlash from customers worried that the tool might help attackers. Thomas's argument is simple: "Do you want the information and knowledge to be accessible to you, or do you want it to be hidden and used by only the people who are malicious?"

Advertisement

Rapid7's first product based on ­Metasploit streamlines the testing process and makes it easier for nontechnical users to check their systems. Now the company will focus on creating more products to help customers identify the problems in their systems and fix them efficiently.

Print

To comment, please sign in or register

Forgot my password

Advertisement

MAGAZINE

Can We Build Tomorrow's Breakthroughs?

Manufacturing in the United States is in trouble. That's bad news not just for the country's economy but for the future of innovation.

Sponsored Content

Technologies from National Instruments

Taking a Measurement
Learn how to use your PC to take measurements

> Click here for more National Instruments Videos <
Whitepaper

BUILD VERSUS BUY
Understanding the Total Cost of Embedded Design

National Instruments has gathered customer information and data regarding some of the cost differences between building a custom solution versus using NI off-the-shelf tools. Using this data, we built the Graphical System Design ‘Build vs. Buy’ Calculator. The calculator can help show the financial differences between building a custom solution versus buying an off-the-shelf system. This paper discusses the benefits and drawbacks of both a traditional custom design approach and off-the-shelf embedded tools.

View full PDF > Listen to story >
Find us on Youtube

Videos

A Robot Recruit that Can Do It All

More

Advertisement

Technology Review Lists

TR50

Our list of the 50 most innovative companies, including the following:

Applied Materials

Zynga

Square

SpaceX

More

Advertisement

Facebook

Advertisement