Re: CRIME Span time from vulnerability to patch for HTTPD servers

From: Crispin Cowan (crispin@private)
Date: Wed Nov 19 2003 - 14:22:02 PST

  • Next message: Crispin Cowan: "Re: FW: CRIME I read your email...No, Really. (The Patriot Act)"

    Quinby, Kris (MED) wrote:
    >I am looking to compare the span time from vulnerability to patch for a few
    >different HTTPD servers.  The vulnerabilities data base at
    > does not list a date associated with the
    >solution, only the announced date.  I also know that the announced date does
    >not necessarily coincide with the discovered date but I will take any
    >information I can find at this point.
    >Does someone know where I can find this type of information?
    It is not recent, but Jim Reavis' study from 1999 provides this kind of
    Note that "faster" is not the only metric you care about: "correctly"
    also matters, as we cover in this 2002 paper:
        "Timing the Application of Security Patches for Optimal Uptime".
        Steve Beattie, Seth Arnold, Crispin Cowan, Perry Wagle, Chris
        Wright, and Adam Shostack.  Presented at the USENIX 16^th Systems
        Administration Conference (LISA 2002)
        <>, Philadelphia, PA, December
        2002. Postscript
        or ugly PDF
    Recently, Microsoft has threatened
    <> :) to
    repeat this study, but they do not appear to explicitly cite Reavis.
    Whether you buy into studies sponsored by Microsoft (with their colorful
    <> track
    <> record
    is up to you.
    Crispin Cowan, Ph.D. 
    Chief Scientist, Immunix

    This archive was generated by hypermail 2b30 : Wed Nov 19 2003 - 15:08:31 PST