Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

US Gov Says Software Measurability is ‘Hardest Problem to Solve’

White House calls for the “timely, complete, and consistent” publication of CVE and CWE data to help solve the security metrics problem.

Are SBOMs Failing?

The US government is calling on software manufacturers to publish “timely, complete, and consistent” documentation of security vulnerabilities to help improve efforts at measuring the quality and safety of code being generated.

A new technical report from the White House Office of the National Cyber Director (ONCD) said transparency around vulnerability documentation should include Common Vulnerability and Exposures (CVE) data and Common Weakness Enumeration (CWE) to help efforts to develop empirical metrics to effectively measure code.

“To make progress toward securing the digital ecosystem, it is necessary to realign incentives to favor long-term investments. For this realignment to generate ecosystem-wide behavior change, it is critical to develop empirical metrics that measure the cybersecurity quality of software,” the White House said.

“Ongoing work to improve how software quality and security are understood, including coordinated vulnerability disclosure, response programs, and timely CVE records, informs essential decision making throughout the ecosystem,” the government argued, noting that software measurability “is one of the hardest open research problems to address.”

The ONCD report [PDF] warns that the problem requires not only refining existing metrics or tools, but also the pioneering of a new frontier in software engineering and cybersecurity research. 

“By advancing capabilities to measure and evaluate software security, more vulnerabilities can be anticipated and mitigated before software is released. The metrics developed from these measurements will also inform the decision-making of a broad range of stakeholders,” the agency added.

Advertisement. Scroll to continue reading.

The ONCD report noted that analyzing software to evaluate its cybersecurity quality is limited by what can be quantified and warned that traditional methods, like counting known vulnerabilities, “are insufficient and do not necessarily provide insight into future threats or attack vectors.”

The White House also used the report to throw its weight behind an industry-wide push to switch to memory-safe programming languages to reduce vulnerabilities at scale and improve cybersecurity quality across the ecosystem. 

“These approaches will be ambitious undertakings that will require persistent, multi-sector focus for the years to come,” the White House said. “Efforts must be made to proactively eliminate entire categories of software vulnerabilities.”

“One of the most impactful actions software and hardware manufacturers can take is adopting memory safe programming languages. They offer a way to eliminate, not just mitigate, entire bug classes. This is a remarkable opportunity for the technical community to improve the cybersecurity of the entire digital ecosystem.”

Related: Cost of Sandboxing Prompts Shift to Memory-Safe Languages

Related: Five Eyes Agencies Publish Guidance on Memory Safety Bugs

Related: CISA Intros Secure-by-design and Secure-by-default Principles

Related: Project Zero Says Zoom Platform Missed ASLR Exploit Mitigation

Written By

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a security community engagement expert who has built programs at major global brands, including Intel Corp., Bishop Fox and GReAT. Ryan is a founding-director of the Security Tinkerers non-profit, an advisor to early-stage entrepreneurs, and a regular speaker at security conferences around the world.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.