Cover | Table of Contents | Colophon
Single Loss Expectancy (cost)
|
x
|
Expected Annual Rate of Occurrences
|
=
|
Annualized Loss Expectancy (cost/year)
|
http://www.all.net/journal/ntb/cause-and-effect.html
http://hissa.nist.gov/rbac/paper/node5.html).www.llbean.com?)http://www.sans.org/top20.htm), the
number one category of Unix vulnerabilities
reported by survey participants was
BIND
weaknesses. The Berkeley Internet Name Domain (BIND) is the open
source software package that powers the majority of Internet DNS
servers. Again according to SANS, "an inordinate
number" of BIND installations are vulnerable to
well-known (and in many cases, old) exploits.http://www.dogpeople.org.
Suppose also that this person's machine is
configured to use the nameserver ns.someisp.com
for DNS
lookups. Since the name
"www.dogpeople.org" has no meaning
to the routers through which the web query and its responses will
pass, the user's web browser needs to learn the
Internet Protocol (IP) address associated with http://www.dogpeople.org before attempting
the web query.