Vulnerability Management Systems Flawed - Leaving your Enterprise at High Risk presented at bsidesdc 2016

by Gordon Mackay,

Summary : Vulnerability management (VM) solutions and products that are central to every information security program contain a serious “hidden” flaw. This software flaw is interleaved within pattern matching-like algorithms located deep within the foundational core of the most widely used automated VM solutions on the market. As a direct consequence of this flaw, even though these products report a certain level of network security risk, the metric upon which their calculations are based is skewed, resulting in an unintentional gap between the products’ intended information risk measurement and the erroneous measurement actually reported.
This session covers the technical details of the referred to hidden flaw, its consequences and what you can do to limit your exposure.