Home > -English-, Architect, Cloud, Security, Telecom > China National Vulnerability Database gets online

China National Vulnerability Database gets online

Oct.18 2009(Beijing time), China CCTV news reported the release of national vulnerability database of China.

Along with the upsoaring of the Internet applications, the vulnerability number is also in a sharp growth. So the update and automation of vulnerability information is becoming more and more critical for the whole information ssytems. Vulnerability Database is used to research, collect, release, automate the lifecycle of vulnerability management, which is regarded the core of the related activities. Although there have been a series of open source vulnerability database(e.g. OSVDB, etc.), commercial maintained vulnerailibity database(e.g. CERT CVE, Bugtraq, NSFocus VDB, etc.), it’s still regarded very essential to setup one authoritive database for the industry, particularly for government and research organizations.

The China national vulnerability database(CNVDB) is built and operated by CNITSEC, which is famous for its evaluation, cerfication of information security products and services at China. The below is a brief self-intro from its official website:

Conducts vulnerability analysts
Enables evaluation of security risk
Provides IT security evaluation and testing services
Provides evaluation services for information security professionals
Delivers IT security consulting, engineering supervision and R&D services

According to the news report, CNVDB has 40,000+ vulnerability entries, 70,000+ of patch and fix information entries, 10,000,000+ of cyber hacking incidents and victim entries.

China is not the first country to build and operate one national level  VDB. Actually, USA has its VDB online for a few years.

“NVD is the U.S. government repository of standards based vulnerability management data. This data enables automation of vulnerability management, security measurement, and compliance (e.g. FISMA). “

The above is the mission statement of National Vulnerability Database of U.S. The data of NVD till Oct.16 is:

NVD contains:
39269     CVE Vulnerabilities
128    Checklists
182     US-CERT Alerts
2347     US-CERT Vuln Notes
2517    OVAL Queries
Last updated:  10/16/09
CVE Publication rate: 12 vulnerabilities / day

The data of OSVDB is as the below (as is Oct.19 2009):

The database currently covers 58,097 vulnerabilities, spanning 25,683 products, from 4,676 researchers.

  1. November 19th, 2009 at 17:06 | #1

    ,..] sbin.cn is one must read source of information on this issue,..]

  2. October 22nd, 2009 at 11:56 | #2

    Based on the news report, the official name of this national database is: CNVD – China Information Security Vulnerability Database. 20+ security vendors signed the agreement with government on the collaboration on this national vulnerability database – CNVD, among with NSFocus is one of the major contributors.

  3. October 19th, 2009 at 11:40 | #3

    RT @zhaol #China National #Vulnerability Database gets online(#CNVDB): http://bit.ly/36HUID

  4. October 19th, 2009 at 11:10 | #4

    RT: @thedarktangent: RT @security4all: #China National #Vulnerability Database gets online(#CNVDB): http://bit.ly/36HUID (via @zhaol)

  5. October 19th, 2009 at 10:57 | #5

    RT @OSVDB: RT @zhaol #China National #Vulnerability Database gets online(#CNVDB): http://bit.ly/36HUID

  6. October 19th, 2009 at 10:41 | #6

    RT @security4all: #China National #Vulnerability Database gets online(#CNVDB): http://bit.ly/36HUID (via @zhaol)

  7. October 19th, 2009 at 10:40 | #7

    RT @zhaol #China National #Vulnerability Database gets online(#CNVDB): http://bit.ly/36HUID

  8. October 19th, 2009 at 10:10 | #8

    RT: @thedarktangent: RT @security4all: #China National #Vulnerability Database gets online(#CNVDB): http://bit.ly/36HUID (via @zhaol)

  9. October 19th, 2009 at 09:50 | #9

    #China National #Vulnerability Database gets online(#CNVDB): http://bit.ly/36HUID (via @zhaol)

  10. October 19th, 2009 at 09:42 | #10

    #China National #Vulnerability Database gets online(#CNVDB): http://bit.ly/36HUID

  11. October 19th, 2009 at 09:41 | #11

    RT @security4all: #China National #Vulnerability Database gets online(#CNVDB): http://bit.ly/36HUID (via @zhaol)

  12. October 19th, 2009 at 08:50 | #12

    #China National #Vulnerability Database gets online(#CNVDB): http://bit.ly/36HUID (via @zhaol)

  13. October 19th, 2009 at 08:42 | #13

    #China National #Vulnerability Database gets online(#CNVDB): http://bit.ly/36HUID

  1. October 19th, 2009 at 11:11 | #1
  2. October 19th, 2009 at 11:57 | #2
  3. October 19th, 2009 at 13:43 | #3
  4. October 19th, 2009 at 15:31 | #4
  5. October 19th, 2009 at 16:31 | #5
  6. October 20th, 2009 at 01:16 | #6
  7. October 20th, 2009 at 02:15 | #7
  8. October 20th, 2009 at 02:16 | #8
  9. October 20th, 2009 at 10:06 | #9
  10. October 20th, 2009 at 11:06 | #10
  11. October 24th, 2009 at 02:50 | #11
  12. October 24th, 2009 at 02:53 | #12
  13. October 24th, 2009 at 03:50 | #13
*