3Com and its TippingPoint division have formed the Zero Day Initiative (ZDI), aimed at ensuring the responsible disclosure of security flaws, also known as vulnerabilities, in order to make technology more secure for users. The goal of the zero day initiative is to proactively protect businesses as soon as possible against newly discovered vulnerabilities.

As part of the program, 3Com will reward security researchers who responsibly reveal information on newly discovered vulnerabilities, as opposed to publicly posting the potentially harmful information, catching businesses and vendors off-guard and unprotected. 3Com will notify affected vendors of security flaws so they can immediately begin working on a solution, most often in the form of a patch. The vulnerabilities will only be disclosed publicly by 3Com once the affected vendor is able to offer a solution to end users, mitigating the threat. 3Com will also use the information to provide preemptive protection to customers through its TippingPoint Digital Vaccine service. Additionally, 3Com plans to share vulnerability details freely with other security vendors prior to public disclosure.

Vulnerabilities enable attackers to gain control of a system for malicious purposes. They can also result in worms or Denial of Service attacks, which can bring down entire networks. Zero day disclosure occurs when the discoverer of the vulnerability discloses the flaw to the public without notifying the vendor, putting businesses at risk from the time of disclosure until the affected vendor issues a patch. It can take vendors weeks or months to supply a patch. For more information, please visit www.zerodayinitiative.com.