SecurityRatty :: tag: reduce
Featured Articles :: Hospitals reduce cost of electronic medical records :: Smaller footprint, less risk :: MS08-067 and the SDL :: SDL and the XSS Filter :: Security is not all about Security Updates :: Should We Treat Contractors The Same as Employees? :: Models and Reductionism - Reducing Clouds Into Streams :: Oh No! Security Metrics! :: On virtualisation :: Fuzz Testing at Microsoft and the Triage Process
...Reduce exposure to make it less likely the event will happen
Take steps to reduce the impact you'll sustain if it does happen Risk purists will argue that you can also transfer the risk, but I'd argue that's really just an extension of #2... In the transferred risk model, we let another entity - like an insurance company - share some of the...
...reduce security vulnerabilities. In theory, if one facet of the SDL process fails to prevent or catch a bug, then some other facet should prevent or catch the bug. The SDL also mandates the use of security defenses, because we know full well that the SDL process will never catch all security bugs. As we have said many times, the goal of the...
...reduce vulnerability to XSS attacks. Our focus has been on improving the ways that web page developers code their pages, and weve developed a lot of tools and techniques for making web content safer from XSS attacks and for detecting XSS vulnerabilities in live pages. The SDL requires the use of many of these tools and techniques, and were...
...reduce the number of vulnerabilities that creep into the software's design and code. I want to emphasize this point because this is the single most important goal of the SDL: To reduce the number of vulnerabilities in software products. This is not about who can fix bugs faster, SDL is about reducing the chance that vulnerabilities are added...
...reduce the Frequency of Loss Events for our populations (W2, 1099). Now for any threat community, we can do one of three things
1.) Reduce the Frequency of Contact
This is really either blocking, cordoning, obfuscation, what have you. For W2s and 1099s our ability to reduce Frequency of Contact may be limited
2.) Reduce the Probability of...
...reduce complexity
CEP was envisioned todiscover causal relationships in complex, uncertain,cloudydataand the current state-of-the-art of software from the streaming SQL vendors do not have this capability, unless you reduce all event models to ordered sets of streaming data (reduce POSETS to TOSETS
Reductionismcan bea valid technique, of...
...reduce the number of patches they need to apply to their products once in deployment. It costs them time and money to deploy security updates. The primary metric that matters to customers is the number of security updates they need to apply. And the only way to reduce the number of updates is to systematically reduce the number and severity...
...Reduce the attack surface By disabling emulated devices, features and services you don't need you reduce the amount of code exposed to an attacker, thus reducing the number of possible bugs that can be exploited. You should also aim to protect the integrity of the guest operating system, making it harder for an attacker to get lower level...
...reduce the chance of having to look at duplicates during the triaging process. This was accomplished by creating unique bucket ids calculated from the stack trace using both symbols and offset when the information is available. The bucket id was used to name a folder that was created in the file system to refer to a unique application...