SlideShare a Scribd company logo
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
Why are you not updating?
The effectiveness of
Software Updates against
Advanced Persistent
Threats Campaigns
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 830929 and No
952647
Giorgio Di Tizio1, Michele Armellini1, Fabio Massacci1,2
1University of Trento
2Vrije Universiteit Amsterdam
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
2
Facing APTs
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
3
Facing APTs: Where is the Truth?
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
4
The Software Update Problem
• Software updates reduce the opportunity for exploitation but can introduce breaking
changes in a software product
• Reservation, disclosure, and exploitation of software vulnerabilities in a software product
can occur at any time before or after the release of an update
• If and when to apply an update is thus a complex problem. Enterprises can decide to:
• Update immediately
• Wait some time to perform regression testing and then update
• Skip the update
• In reality, enterprises struggle to keep up with the updates and wait several months
before deploying one
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
5
Investigate the APTs
• We collected information about more than 350
campaigns performed by 86 APTs in more than
10 years
• We enriched data about APTs with information
about CVEs, software versions affected, and
available updates
• We looked at the effectiveness of keeping the
software up-to-date for 5 widely used software
products in the decade under study (Office,
Acrobat Reader, Air, JRE, and Flash Player) from
three major software companies (Microsoft,
Adobe, and Oracle)
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
6
The APTs Landscape: Attack Vectors and Targeted Software
• Spear phishing is the favorite attack vector employed with or without a software
vulnerability.
• In more than 50% of the cases having software up to date does not make any difference
• Office, Flash Player, Acrobat Reader, Air, and JRE are the most exploited client-side
products grouped by vendor
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
7
The APTs Landscape: Preference on Software Vulnerabilities
• Observed a total of 118 unique software vulnerabilities exploited by APTs
• Only 8 out of 86 APTs did not share any software vulnerability with other groups in their
campaigns
Campaigns exploiting at least a publicly
known vulnerability in NVD
Campaigns exploiting at least a reserved
vulnerability in NVD
Campaigns exploiting at least an unknown
vulnerability
119
10
24
2
1
3
3
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
8
Effectiveness and Cost of Software Update Strategies
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
9
Effectiveness and Cost of Software Update Strategies
Ideal: update to each newest
version as soon as it is
available from the vendor
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
10
Effectiveness and Cost of Software Update Strategies
Industry:
update to each
newest
version but
with a delay of
1 month
before
deployment
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
11
Effectiveness and Cost of Software Update Strategies
Reactive: update
to the first new
(not vulnerable)
version when a
CVE is publicly
available in NVD
with a delay of 1
month before
deployment
Grant Agreement 952647
Project Title Assurance and certification in secure Multi-
party Open Software and Services
Project Acronym AssureMOSS
Project Start Date 01 October 2020
Number of Deliverable XX
Report title XXX
Related Work Package WPX: XXX
Related Task(s) TX.X: XXX
Lead organization XXX
Submission date: Day Month Year
Last Change Date Day Month Year
Dissemination Level Confidential/Public
This project has received funding from the European Union’s Horizon 2020
research and innovation programme under grant agreement No 952647
PRESENTATION
TEMPLATE
12
Software Update Strategies against APTs
• We built a structured, manually verified dataset of 86 APTs and more than 350
campaigns based on an exhaustive search of over 500 technical reports and blogs
• We investigated the effectiveness of software updates against APTs
• Key Takeaways:
• Most APTs are not as sophisticated in their initial access as we think and prefer to exploit
publicly known vulnerabilities
• The effectiveness of an update strategy that is reactive on the publicly known vulnerable
releases has the same risk profile as a strategy that always updates with a delay but costs
significantly less in terms of updates
• More details in our IEEE TSE paper: https://doi.org/10.1109/TSE.2022.3176674
• Check out our APT Dataset using the QR code

More Related Content

Similar to SFScon 22 - Giorgio Di Tizio - Why are you not updating The effectiveness of Software Updates against Advanced Persistent Threats Campaigns.pdf

Ncc Group Escrow Overview 2010
Ncc Group Escrow Overview 2010Ncc Group Escrow Overview 2010
Ncc Group Escrow Overview 2010
Jonnyhyde
 
Running faster market exploration with the cloud teams campaigns
Running faster market exploration with the cloud teams campaignsRunning faster market exploration with the cloud teams campaigns
Running faster market exploration with the cloud teams campaigns
Dimitris Papaspyros
 
Research Software Sustainability takes a Village
Research Software Sustainability takes a VillageResearch Software Sustainability takes a Village
Research Software Sustainability takes a Village
Carole Goble
 
Starting an Open Source Program Office (OSPO)
Starting an Open Source Program Office (OSPO)Starting an Open Source Program Office (OSPO)
Starting an Open Source Program Office (OSPO)
Chris Aniszczyk
 
Helix Nebula - The Science Cloud - Lessons learned
Helix Nebula - The Science Cloud - Lessons learned Helix Nebula - The Science Cloud - Lessons learned
Helix Nebula - The Science Cloud - Lessons learned
Helix Nebula The Science Cloud
 
CloudTeams Presentation for the SE4SA Cluster in NetFutures2016
CloudTeams Presentation for the SE4SA Cluster in NetFutures2016CloudTeams Presentation for the SE4SA Cluster in NetFutures2016
CloudTeams Presentation for the SE4SA Cluster in NetFutures2016
CloudTeams
 
The Helix Nebula Pre-Commercial Procurement - 1° Asterics-Obelics Workshop
The Helix Nebula Pre-Commercial Procurement - 1° Asterics-Obelics WorkshopThe Helix Nebula Pre-Commercial Procurement - 1° Asterics-Obelics Workshop
The Helix Nebula Pre-Commercial Procurement - 1° Asterics-Obelics Workshop
Helix Nebula The Science Cloud
 
ATC iLab - profile & current projects
ATC iLab - profile & current projectsATC iLab - profile & current projects
ATC iLab - profile & current projects
Athens Technology Center
 
XDC Overview
XDC OverviewXDC Overview
XDC Overview
EXICON Ltd.
 
What is needed to start trusting the security of your applications in the cloud?
What is needed to start trusting the security of your applications in the cloud?What is needed to start trusting the security of your applications in the cloud?
What is needed to start trusting the security of your applications in the cloud?
PECB
 
Module 1 - Evolution to Secure DevOps.pptx
Module 1 - Evolution to Secure DevOps.pptxModule 1 - Evolution to Secure DevOps.pptx
Module 1 - Evolution to Secure DevOps.pptx
aaronpham13
 
Odc & bot octetis eng
Odc & bot octetis engOdc & bot octetis eng
Odc & bot octetis eng
Ira42
 
Horizon 6 what's new
Horizon 6   what's newHorizon 6   what's new
Horizon 6 what's new
培林 何
 
CTO-Cybersecurity Forum-Angela McKay
CTO-Cybersecurity Forum-Angela McKayCTO-Cybersecurity Forum-Angela McKay
CTO-Cybersecurity Forum-Angela McKaysegughana
 
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Black Duck by Synopsys
 
Digital Government Strategy—Percussion Enables Compliance
Digital Government Strategy—Percussion Enables ComplianceDigital Government Strategy—Percussion Enables Compliance
Digital Government Strategy—Percussion Enables Compliance
Percussion Software
 
Why Governments Depend on Open Source for Secure, Private Email
Why Governments Depend on Open Source for Secure, Private EmailWhy Governments Depend on Open Source for Secure, Private Email
Why Governments Depend on Open Source for Secure, Private Email
All Things Open
 
i4Trust_Data Spaces for effective and trusted data sharing.pptx
 i4Trust_Data Spaces for effective and trusted data sharing.pptx i4Trust_Data Spaces for effective and trusted data sharing.pptx
i4Trust_Data Spaces for effective and trusted data sharing.pptx
FIWARE
 
Etherisc at the Ethereum Meetup Vienna 20 March 2017 (Part 1)
Etherisc at the Ethereum Meetup Vienna 20 March 2017 (Part 1)Etherisc at the Ethereum Meetup Vienna 20 March 2017 (Part 1)
Etherisc at the Ethereum Meetup Vienna 20 March 2017 (Part 1)
Stephan Karpischek
 
Open Source Insight: Open Source 360 Survey, DockerCon 2017, & More on the Cl...
Open Source Insight: Open Source 360 Survey, DockerCon 2017, & More on the Cl...Open Source Insight: Open Source 360 Survey, DockerCon 2017, & More on the Cl...
Open Source Insight: Open Source 360 Survey, DockerCon 2017, & More on the Cl...
Black Duck by Synopsys
 

Similar to SFScon 22 - Giorgio Di Tizio - Why are you not updating The effectiveness of Software Updates against Advanced Persistent Threats Campaigns.pdf (20)

Ncc Group Escrow Overview 2010
Ncc Group Escrow Overview 2010Ncc Group Escrow Overview 2010
Ncc Group Escrow Overview 2010
 
Running faster market exploration with the cloud teams campaigns
Running faster market exploration with the cloud teams campaignsRunning faster market exploration with the cloud teams campaigns
Running faster market exploration with the cloud teams campaigns
 
Research Software Sustainability takes a Village
Research Software Sustainability takes a VillageResearch Software Sustainability takes a Village
Research Software Sustainability takes a Village
 
Starting an Open Source Program Office (OSPO)
Starting an Open Source Program Office (OSPO)Starting an Open Source Program Office (OSPO)
Starting an Open Source Program Office (OSPO)
 
Helix Nebula - The Science Cloud - Lessons learned
Helix Nebula - The Science Cloud - Lessons learned Helix Nebula - The Science Cloud - Lessons learned
Helix Nebula - The Science Cloud - Lessons learned
 
CloudTeams Presentation for the SE4SA Cluster in NetFutures2016
CloudTeams Presentation for the SE4SA Cluster in NetFutures2016CloudTeams Presentation for the SE4SA Cluster in NetFutures2016
CloudTeams Presentation for the SE4SA Cluster in NetFutures2016
 
The Helix Nebula Pre-Commercial Procurement - 1° Asterics-Obelics Workshop
The Helix Nebula Pre-Commercial Procurement - 1° Asterics-Obelics WorkshopThe Helix Nebula Pre-Commercial Procurement - 1° Asterics-Obelics Workshop
The Helix Nebula Pre-Commercial Procurement - 1° Asterics-Obelics Workshop
 
ATC iLab - profile & current projects
ATC iLab - profile & current projectsATC iLab - profile & current projects
ATC iLab - profile & current projects
 
XDC Overview
XDC OverviewXDC Overview
XDC Overview
 
What is needed to start trusting the security of your applications in the cloud?
What is needed to start trusting the security of your applications in the cloud?What is needed to start trusting the security of your applications in the cloud?
What is needed to start trusting the security of your applications in the cloud?
 
Module 1 - Evolution to Secure DevOps.pptx
Module 1 - Evolution to Secure DevOps.pptxModule 1 - Evolution to Secure DevOps.pptx
Module 1 - Evolution to Secure DevOps.pptx
 
Odc & bot octetis eng
Odc & bot octetis engOdc & bot octetis eng
Odc & bot octetis eng
 
Horizon 6 what's new
Horizon 6   what's newHorizon 6   what's new
Horizon 6 what's new
 
CTO-Cybersecurity Forum-Angela McKay
CTO-Cybersecurity Forum-Angela McKayCTO-Cybersecurity Forum-Angela McKay
CTO-Cybersecurity Forum-Angela McKay
 
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
 
Digital Government Strategy—Percussion Enables Compliance
Digital Government Strategy—Percussion Enables ComplianceDigital Government Strategy—Percussion Enables Compliance
Digital Government Strategy—Percussion Enables Compliance
 
Why Governments Depend on Open Source for Secure, Private Email
Why Governments Depend on Open Source for Secure, Private EmailWhy Governments Depend on Open Source for Secure, Private Email
Why Governments Depend on Open Source for Secure, Private Email
 
i4Trust_Data Spaces for effective and trusted data sharing.pptx
 i4Trust_Data Spaces for effective and trusted data sharing.pptx i4Trust_Data Spaces for effective and trusted data sharing.pptx
i4Trust_Data Spaces for effective and trusted data sharing.pptx
 
Etherisc at the Ethereum Meetup Vienna 20 March 2017 (Part 1)
Etherisc at the Ethereum Meetup Vienna 20 March 2017 (Part 1)Etherisc at the Ethereum Meetup Vienna 20 March 2017 (Part 1)
Etherisc at the Ethereum Meetup Vienna 20 March 2017 (Part 1)
 
Open Source Insight: Open Source 360 Survey, DockerCon 2017, & More on the Cl...
Open Source Insight: Open Source 360 Survey, DockerCon 2017, & More on the Cl...Open Source Insight: Open Source 360 Survey, DockerCon 2017, & More on the Cl...
Open Source Insight: Open Source 360 Survey, DockerCon 2017, & More on the Cl...
 

More from South Tyrol Free Software Conference

SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...
SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...
SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...
South Tyrol Free Software Conference
 
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...
South Tyrol Free Software Conference
 
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data Hub
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data HubSFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data Hub
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data Hub
South Tyrol Free Software Conference
 
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...
South Tyrol Free Software Conference
 
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...
South Tyrol Free Software Conference
 
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...
South Tyrol Free Software Conference
 
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelines
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelinesSFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelines
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelines
South Tyrol Free Software Conference
 
SFSCON23 - Christian Busse - Free Software and Open Science
SFSCON23 - Christian Busse - Free Software and Open ScienceSFSCON23 - Christian Busse - Free Software and Open Science
SFSCON23 - Christian Busse - Free Software and Open Science
South Tyrol Free Software Conference
 
SFSCON23 - Charles H. Schulz - Why open digital infrastructure matters
SFSCON23 - Charles H. Schulz - Why open digital infrastructure mattersSFSCON23 - Charles H. Schulz - Why open digital infrastructure matters
SFSCON23 - Charles H. Schulz - Why open digital infrastructure matters
South Tyrol Free Software Conference
 
SFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portal
SFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portalSFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portal
SFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portal
South Tyrol Free Software Conference
 
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...
South Tyrol Free Software Conference
 
SFSCON23 - Stefan Mutschlechner - Smart Werke Meran
SFSCON23 - Stefan Mutschlechner - Smart Werke MeranSFSCON23 - Stefan Mutschlechner - Smart Werke Meran
SFSCON23 - Stefan Mutschlechner - Smart Werke Meran
South Tyrol Free Software Conference
 
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...
South Tyrol Free Software Conference
 
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free software
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free softwareSFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free software
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free software
South Tyrol Free Software Conference
 
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...
South Tyrol Free Software Conference
 
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changer
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changerSFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changer
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changer
South Tyrol Free Software Conference
 
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...
South Tyrol Free Software Conference
 
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation Internet
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation InternetSFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation Internet
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation Internet
South Tyrol Free Software Conference
 
SFSCON23 - Edoardo Scepi - The Brand-New Version of IGis Maps
SFSCON23 - Edoardo Scepi - The Brand-New Version of IGis MapsSFSCON23 - Edoardo Scepi - The Brand-New Version of IGis Maps
SFSCON23 - Edoardo Scepi - The Brand-New Version of IGis Maps
South Tyrol Free Software Conference
 
SFSCON23 - Davide Vernassa - Empowering Insights Unveiling the latest innova...
SFSCON23 - Davide Vernassa - Empowering Insights  Unveiling the latest innova...SFSCON23 - Davide Vernassa - Empowering Insights  Unveiling the latest innova...
SFSCON23 - Davide Vernassa - Empowering Insights Unveiling the latest innova...
South Tyrol Free Software Conference
 

More from South Tyrol Free Software Conference (20)

SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...
SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...
SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...
 
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...
 
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data Hub
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data HubSFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data Hub
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data Hub
 
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...
 
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...
 
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...
 
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelines
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelinesSFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelines
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelines
 
SFSCON23 - Christian Busse - Free Software and Open Science
SFSCON23 - Christian Busse - Free Software and Open ScienceSFSCON23 - Christian Busse - Free Software and Open Science
SFSCON23 - Christian Busse - Free Software and Open Science
 
SFSCON23 - Charles H. Schulz - Why open digital infrastructure matters
SFSCON23 - Charles H. Schulz - Why open digital infrastructure mattersSFSCON23 - Charles H. Schulz - Why open digital infrastructure matters
SFSCON23 - Charles H. Schulz - Why open digital infrastructure matters
 
SFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portal
SFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portalSFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portal
SFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portal
 
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...
 
SFSCON23 - Stefan Mutschlechner - Smart Werke Meran
SFSCON23 - Stefan Mutschlechner - Smart Werke MeranSFSCON23 - Stefan Mutschlechner - Smart Werke Meran
SFSCON23 - Stefan Mutschlechner - Smart Werke Meran
 
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...
 
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free software
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free softwareSFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free software
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free software
 
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...
 
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changer
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changerSFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changer
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changer
 
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...
 
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation Internet
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation InternetSFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation Internet
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation Internet
 
SFSCON23 - Edoardo Scepi - The Brand-New Version of IGis Maps
SFSCON23 - Edoardo Scepi - The Brand-New Version of IGis MapsSFSCON23 - Edoardo Scepi - The Brand-New Version of IGis Maps
SFSCON23 - Edoardo Scepi - The Brand-New Version of IGis Maps
 
SFSCON23 - Davide Vernassa - Empowering Insights Unveiling the latest innova...
SFSCON23 - Davide Vernassa - Empowering Insights  Unveiling the latest innova...SFSCON23 - Davide Vernassa - Empowering Insights  Unveiling the latest innova...
SFSCON23 - Davide Vernassa - Empowering Insights Unveiling the latest innova...
 

Recently uploaded

May Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdfMay Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdf
Adele Miller
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
Drona Infotech
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
abdulrafaychaudhry
 
AI Genie Review: World’s First Open AI WordPress Website Creator
AI Genie Review: World’s First Open AI WordPress Website CreatorAI Genie Review: World’s First Open AI WordPress Website Creator
AI Genie Review: World’s First Open AI WordPress Website Creator
Google
 
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
Łukasz Chruściel
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
Safe Software
 
Large Language Models and the End of Programming
Large Language Models and the End of ProgrammingLarge Language Models and the End of Programming
Large Language Models and the End of Programming
Matt Welsh
 
Graspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code AnalysisGraspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code Analysis
Aftab Hussain
 
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Globus
 
Game Development with Unity3D (Game Development lecture 3)
Game Development  with Unity3D (Game Development lecture 3)Game Development  with Unity3D (Game Development lecture 3)
Game Development with Unity3D (Game Development lecture 3)
abdulrafaychaudhry
 
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing SuiteAI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
Google
 
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket ManagementUtilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate
 
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Łukasz Chruściel
 
Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"
Donna Lenk
 
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of CodeA Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
Aftab Hussain
 
Enterprise Resource Planning System in Telangana
Enterprise Resource Planning System in TelanganaEnterprise Resource Planning System in Telangana
Enterprise Resource Planning System in Telangana
NYGGS Automation Suite
 
Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024
Globus
 
Enterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptxEnterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptx
QuickwayInfoSystems3
 
Atelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissancesAtelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissances
Neo4j
 
Empowering Growth with Best Software Development Company in Noida - Deuglo
Empowering Growth with Best Software  Development Company in Noida - DeugloEmpowering Growth with Best Software  Development Company in Noida - Deuglo
Empowering Growth with Best Software Development Company in Noida - Deuglo
Deuglo Infosystem Pvt Ltd
 

Recently uploaded (20)

May Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdfMay Marketo Masterclass, London MUG May 22 2024.pdf
May Marketo Masterclass, London MUG May 22 2024.pdf
 
Mobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona InfotechMobile App Development Company In Noida | Drona Infotech
Mobile App Development Company In Noida | Drona Infotech
 
Lecture 1 Introduction to games development
Lecture 1 Introduction to games developmentLecture 1 Introduction to games development
Lecture 1 Introduction to games development
 
AI Genie Review: World’s First Open AI WordPress Website Creator
AI Genie Review: World’s First Open AI WordPress Website CreatorAI Genie Review: World’s First Open AI WordPress Website Creator
AI Genie Review: World’s First Open AI WordPress Website Creator
 
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf2024 eCommerceDays Toulouse - Sylius 2.0.pdf
2024 eCommerceDays Toulouse - Sylius 2.0.pdf
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
 
Large Language Models and the End of Programming
Large Language Models and the End of ProgrammingLarge Language Models and the End of Programming
Large Language Models and the End of Programming
 
Graspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code AnalysisGraspan: A Big Data System for Big Code Analysis
Graspan: A Big Data System for Big Code Analysis
 
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
Climate Science Flows: Enabling Petabyte-Scale Climate Analysis with the Eart...
 
Game Development with Unity3D (Game Development lecture 3)
Game Development  with Unity3D (Game Development lecture 3)Game Development  with Unity3D (Game Development lecture 3)
Game Development with Unity3D (Game Development lecture 3)
 
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing SuiteAI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
 
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket ManagementUtilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
Utilocate provides Smarter, Better, Faster, Safer Locate Ticket Management
 
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️Need for Speed: Removing speed bumps from your Symfony projects ⚡️
Need for Speed: Removing speed bumps from your Symfony projects ⚡️
 
Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"Navigating the Metaverse: A Journey into Virtual Evolution"
Navigating the Metaverse: A Journey into Virtual Evolution"
 
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of CodeA Study of Variable-Role-based Feature Enrichment in Neural Models of Code
A Study of Variable-Role-based Feature Enrichment in Neural Models of Code
 
Enterprise Resource Planning System in Telangana
Enterprise Resource Planning System in TelanganaEnterprise Resource Planning System in Telangana
Enterprise Resource Planning System in Telangana
 
Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024Globus Compute Introduction - GlobusWorld 2024
Globus Compute Introduction - GlobusWorld 2024
 
Enterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptxEnterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptx
 
Atelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissancesAtelier - Innover avec l’IA Générative et les graphes de connaissances
Atelier - Innover avec l’IA Générative et les graphes de connaissances
 
Empowering Growth with Best Software Development Company in Noida - Deuglo
Empowering Growth with Best Software  Development Company in Noida - DeugloEmpowering Growth with Best Software  Development Company in Noida - Deuglo
Empowering Growth with Best Software Development Company in Noida - Deuglo
 

SFScon 22 - Giorgio Di Tizio - Why are you not updating The effectiveness of Software Updates against Advanced Persistent Threats Campaigns.pdf

  • 1. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE Why are you not updating? The effectiveness of Software Updates against Advanced Persistent Threats Campaigns This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 830929 and No 952647 Giorgio Di Tizio1, Michele Armellini1, Fabio Massacci1,2 1University of Trento 2Vrije Universiteit Amsterdam
  • 2. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE 2 Facing APTs
  • 3. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE 3 Facing APTs: Where is the Truth?
  • 4. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE 4 The Software Update Problem • Software updates reduce the opportunity for exploitation but can introduce breaking changes in a software product • Reservation, disclosure, and exploitation of software vulnerabilities in a software product can occur at any time before or after the release of an update • If and when to apply an update is thus a complex problem. Enterprises can decide to: • Update immediately • Wait some time to perform regression testing and then update • Skip the update • In reality, enterprises struggle to keep up with the updates and wait several months before deploying one
  • 5. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE 5 Investigate the APTs • We collected information about more than 350 campaigns performed by 86 APTs in more than 10 years • We enriched data about APTs with information about CVEs, software versions affected, and available updates • We looked at the effectiveness of keeping the software up-to-date for 5 widely used software products in the decade under study (Office, Acrobat Reader, Air, JRE, and Flash Player) from three major software companies (Microsoft, Adobe, and Oracle)
  • 6. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE 6 The APTs Landscape: Attack Vectors and Targeted Software • Spear phishing is the favorite attack vector employed with or without a software vulnerability. • In more than 50% of the cases having software up to date does not make any difference • Office, Flash Player, Acrobat Reader, Air, and JRE are the most exploited client-side products grouped by vendor
  • 7. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE 7 The APTs Landscape: Preference on Software Vulnerabilities • Observed a total of 118 unique software vulnerabilities exploited by APTs • Only 8 out of 86 APTs did not share any software vulnerability with other groups in their campaigns Campaigns exploiting at least a publicly known vulnerability in NVD Campaigns exploiting at least a reserved vulnerability in NVD Campaigns exploiting at least an unknown vulnerability 119 10 24 2 1 3 3
  • 8. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE 8 Effectiveness and Cost of Software Update Strategies
  • 9. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE 9 Effectiveness and Cost of Software Update Strategies Ideal: update to each newest version as soon as it is available from the vendor
  • 10. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE 10 Effectiveness and Cost of Software Update Strategies Industry: update to each newest version but with a delay of 1 month before deployment
  • 11. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE 11 Effectiveness and Cost of Software Update Strategies Reactive: update to the first new (not vulnerable) version when a CVE is publicly available in NVD with a delay of 1 month before deployment
  • 12. Grant Agreement 952647 Project Title Assurance and certification in secure Multi- party Open Software and Services Project Acronym AssureMOSS Project Start Date 01 October 2020 Number of Deliverable XX Report title XXX Related Work Package WPX: XXX Related Task(s) TX.X: XXX Lead organization XXX Submission date: Day Month Year Last Change Date Day Month Year Dissemination Level Confidential/Public This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952647 PRESENTATION TEMPLATE 12 Software Update Strategies against APTs • We built a structured, manually verified dataset of 86 APTs and more than 350 campaigns based on an exhaustive search of over 500 technical reports and blogs • We investigated the effectiveness of software updates against APTs • Key Takeaways: • Most APTs are not as sophisticated in their initial access as we think and prefer to exploit publicly known vulnerabilities • The effectiveness of an update strategy that is reactive on the publicly known vulnerable releases has the same risk profile as a strategy that always updates with a delay but costs significantly less in terms of updates • More details in our IEEE TSE paper: https://doi.org/10.1109/TSE.2022.3176674 • Check out our APT Dataset using the QR code