Security flaws are endemic to modern computer software. Software vendors have largely ignored security flaws in the past, believing that they could fix problems by patching flaws after the software was released and an attacker discovered the flaw. However, expanding software complexity is increasing the number of security bugs. At the same time, ever greater network connectivity is offering adversaries greater opportunities to attack software. Therefore, we can no longer afford to ignore security flaws until they are exploited by an attacker.