Software Security and the “Hamster Wheel of Pain”
Andrew J. Stewart · Cornell University Press eBooks · 2021
This chapter assesses how the feedback loop that emerged during the dot-com boom had created an ever-increasing number of new vulnerabilities that organizations needed to respond to by applying security patches. At the heart of the perimeter model of security was the firewall, but an organization's firewall had to permit web traffic to reach the organization's web server. If the web server had a vulnerability, which it almost certainly would experience over time, a hacker could compromise its security and likely then compromise the security of the operating system on which the web server was running. A desire for the focus of security efforts to be placed on operating system security was a curious return to the thinking of the 1970s and 1980s. Microsoft is best known for its computer software, and so its security efforts have historically been focused on software security. Ultimately, Microsoft was successful in reducing the number of security vulnerabilities in its software, in contributing to the creation of software security as a discipline, and in raising the profile of software security generally.