EMZETT.
Login

Zero-Day

In short: A security vulnerability that’s already known to and exploitable by attackers before the vendor knows about it or was able to provide a patch — the name comes from the vendor having had “zero days” to react.

In more detail: Zero-day exploits are particularly dangerous and valuable (sometimes traded for six-figure sums on the black market), because at the time of the attack there’s no official protection yet — classic antivirus signatures or known patches don’t help. Once the vulnerability becomes public and the vendor releases a patch, it’s no longer a zero-day.

In Depth

The lifecycle of a security vulnerability can be roughly outlined like this:

Vulnerability arises (e.g. a programming error) -> time passes, nobody knows about it
  |
  v
Someone discovers it (attacker OR security researcher)
  |
  +-- Attacker discovers it first -> ZERO-DAY (vendor knows nothing,
  |                                    has "zero days" of lead time to patch)
  |
  +-- Researcher discovers it first -> "responsible disclosure": vendor
                                        is informed in advance, gets time
                                        to patch before it becomes public

Trading in zero-day exploits is its own, sometimes very lucrative market: some security researchers sell discovered vulnerabilities directly to the affected vendor via “bug bounty programmes” (legal, usually with five- to six-figure rewards for critical vulnerabilities at large vendors). Others sell them on the black market or to specialised brokers, who in turn resell them to government agencies or other actors — for particularly critical vulnerabilities (e.g. one that allows a complete remote takeover of an iPhone with no user interaction at all), amounts in the millions have already been paid.

From a defensive point of view, a zero-day vulnerability is by definition not defensible through classic, signature-based detection (there’s no known signature yet, after all) — protection here comes more from behavioural analysis (recognising suspicious process behaviour, even without knowing the specific vulnerability), layered defence (see Security “defence in depth”) and fast responsiveness, as soon as a vulnerability does become known and a patch becomes available.

Well-known historical examples

Stuxnet (discovered in 2010) is considered one of the best-known examples of the targeted use of zero-day exploits: the malware exploited four different, previously unknown Windows vulnerabilities all at once, to specifically sabotage Iranian uranium enrichment facilities by targeting specific industrial control systems — a degree of sophistication and resource investment that pointed to state authorship. The existence of several completely unknown zero-days at once in a single piece of malware impressively demonstrated to the security industry what attack potential well-funded, targeted actors have compared to broadly scattered, opportunistic malware.

Patch management as a central countermeasure

Even though a zero-day is by definition not preventable in advance, its danger usually ends quickly once a patch becomes available — the real residual danger afterwards often arises from delayed installation of updates. Promptly installing security updates (“patch management”) is therefore one of the most effective, yet also one of the most frequently neglected, security measures of all: numerous major security incidents of recent years didn’t use real zero-days at all, but long-known and already-patched vulnerabilities that affected organisations simply hadn’t installed yet — a circumstance often referred to in the industry as an “N-day exploit” (as opposed to a genuine zero-day).

Zero-day brokers as their own industry

Alongside the classic black market, there are legal but ethically controversial companies that specialise in buying and reselling zero-day exploits — they buy vulnerabilities found by security researchers and sell them exclusively to well-funded customers, often government agencies, instead of reporting them to the affected vendor. This creates an economic incentive that directly opposes the “responsible disclosure” principle: a researcher often earns considerably more from an unreported vulnerability than through a vendor’s regular bug bounty programme, which raises the question of how the free market for security vulnerabilities affects overall internet security in the long run.

See also: Pegasus