News: 1604383331

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

CERT/CC: 'Sensational' bug names spark fear, hype – so we'll give flaws our own labels... like Suggestive Bunny

(2020/11/03)


Many memorable events get named, whether they're hurricanes, political events, or security incidents like the Morris Worm, which surfaced 32 years ago yesterday.

But named security incidents recently have editorialized their own importance with fear-mongering monikers like Heartbleed (2014), Meltdown, Spectre, and Foreshadow (2018), and Fallout and ZombieLoad (2019).

Not all do so. There have been less emotionally loaded bug names proposed, like CacheOut, CrossTalk, and RIDL, but name-amplified alarmism has become prevalent enough to prompt the infosec experts at the CERT cybersecurity division of Carnegie Mellon University's Software Engineering Institute, to intervene.

Last month, the CERT/CC began applying names to Common Vulnerabilities and Exposures (CVE) identifiers, to make them easier to recall and less likely to cause concern.

"Sensational names are often the tool of the discoverers to create more visibility for their work," [1]explained Leigh Metcalf, senior network security research analyst at the CMU's CERT/CC, on Friday. "This is an area of concern for the CERT/CC as we attempt to reduce any fear, uncertainty, and doubt for vendors, researchers, and the general public."

The impetus for the initiative, Metcalf suggests, is that such names shape public policy debates, such as the 2018 US government hearings that mentioned Meltdown and Spectre.

US-CERT lists the 10 most-exploited security bugs and, yeah, it's mostly Microsoft holes people forgot to patch [2]READ MORE

On October 16, via the Twitter bot dubbed [3]Vulnonym , CERT/CC began proposing randomized adjective noun combinations for CVE designations. So instead of referring to vulnerabilities like the recent [4]Windows kernel flaw with a yawn-inducing identifier like CVE-2020-17087, the group is proposing auto-assembled nicknames like Unsure Ensemble, Shapeless Screwdriver, and Unmarked Slapstick. And [5]Suggestive Bunny .

Metcalf says the goal is to create "neutral names" that manage to be memorable without commenting on the severity of the flaw.

CERT's naming scheme draws from a list of adjectives and nouns culled from Wiktionary and various word categories like animals, plants, space objects, and so on. These then get mapped to the digits in the CVE number using the Cantor Depairing Function. The results often sound like [6]Ubuntu Linux release code names.

"When tackling this problem, we considered several lists of words to ensure no sensational, scary, or offensive names were included," explained Metcalf, perhaps unaware that CVE-2020-9875 was dubbed [7]Scary Seine .

But neutral language is a challenge because individually innocuous words may become less so in combination and because context matters when it comes to meaning. Some of the names issued invite a snicker on their own, like [8]Canny Lumpsucker .

Others might be seen as provocative, if [9]Grizzled Serf referred to an Amazon-related vulnerability or [10]Filthy Python referred to a flaw in an adult toy. And what to make of [11]Headed Bottom and [12]Perceptive Ejaculate ?

At least such issues have been anticipated. Metcalf says there's a simple process to remove offensive names from the data set and regenerate them. She doesn't specify what that process is or propose criteria for assessing objectionable combinations.

Perhaps the complaint process will follow the current standard for customer support – raising a ruckus on social media. ®

Get our [13]Tech Resources



[1] https://insights.sei.cmu.edu/cert/2020/10/vulnonym-stop-the-naming-madness.html

[2] https://www.theregister.com/2020/05/14/uscert_most_pwned_bugs/

[3] https://twitter.com/vulnonym

[4] https://www.theregister.com/2020/10/30/windows_kernel_zeroday/

[5] https://twitter.com/vulnonym/status/1323255946366328835

[6] https://wiki.ubuntu.com/DevelopmentCodeNames

[7] https://twitter.com/vulnonym/status/1319403949179441155?s=20

[8] https://twitter.com/vulnonym/status/1319321467109126146?s=20

[9] https://twitter.com/vulnonym/status/1319050809707999233?s=20

[10] https://twitter.com/vulnonym/status/1318990330327420929?s=20

[11] https://twitter.com/vulnonym/status/1319045127084625920?s=20

[12] https://twitter.com/vulnonym/status/1318741967547830272?s=20

[13] https://whitepapers.theregister.com/

Maelstorm

Maybe CERT should take a clue from the military which uses codewords to obfuscate operations, places, people, and things. They are masters of it.

Oh help us...

IGotOut

Based on it's source, how long before

Nazi Jew, Happy Slave or Vaccine Murderer.

Dung

Beau

Mm, so now bugs will have to comply with political correctness. I'm thinking of the Dung Beetle?

Correct Horse

Alan J. Wylie

I can't wait for the next password vulnerability to be called "Correct Horse".

Re: Correct Horse

Kane

[1]Obligatory

[1] https://xkcd.com/936/

Unfortunately...

Ken Moorhouse

Unfortunately Dave Allen is no longer with us. He would have been good at evaluating names.

(I am sure he did a sketch about "scuds" and "patriot missiles").

"there's a simple process to remove offensive names"

Pascal Monett

And it should start by not drawing random words from a 3rd-party website.

Create your vetted list in-house, do not include those scary words you have become so afraid of, avoid including potentially offensive words, and you won't have to have a process to remove anything afterwards.

Of course, that requires a bit more work than just randomly calling on Wiktionary, but if you think about it, it would remove a lot of hassle in the long run.

Spouse, n.:
Someone who'll stand by you through all the trouble you
wouldn't have had if you'd stayed single.