China’s National Vulnerability Database works more than twice as fast on average than its U.S. counterpart, according to new research. On average, U.S.-CERT takes 33 days after the public disclosure of a software vulnerability to complete the cataloging process and create an entry in the National Vulnerability Database (NVD), whereas China’s version (CNNVD) is updated an average of just 13 days after public disclosure, according to research published by cybersecurity firm Recorded Future. In its posting, the firm analyzed two years of vulnerability reporting data from both NVD and CNNVD. Because averages can be distorted by a small number of outlying data points (in this case, very long delays in vulnerability cataloguing) Recorded Future analyzed the data based on percentiles as well. “Within six days of initial disclosure, 75 percent of all vulnerabilities published on the web are covered in CNNVD. The U.S. NVD takes 20 days,” the researchers write. “CNNVD captures […]
The post China’s vulnerability disclosure system twice as fast as U.S. version appeared first on Cyberscoop.
Continue reading China’s vulnerability disclosure system twice as fast as U.S. version→