- Attack code released for new DNS attack
- Parts of SF network still locked out
- Basic to-do apps for iPhone, iPod touch
- Spam King pulls prison vanishing act
- SCO Group: Its future is all used up
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
Currently, the most widespread means of preventing intrusions is patching, and it's failing miserably. The number of security incidents reported to CERT has grown exponentially over the past six years, reaching an all-time high of 137,529 in 2003, which was also the year that the Blaster and MS-SQL Slammer worms caused widespread devastation. Patch management seeks to address these issues through automation that lets patches be installed rapidly and without Herculean human effort. But patch management is of limited benefit. Consider the following:
• Faulty patches can bring down critical servers and cost more to an organization than a security breach. This is an all-too-common scenario: An analysis by WireX Communications and Zero Knowledge Systems indicates that one-fifth of all new patches are revised. Hence, it is very risky to immediately deploy a patch without thorough regression testing to make sure the patch will not cause damage.
• Sometimes vendors do not develop a patch because they mistakenly regard a vulnerability as unimportant or they do not have the time and resources to do so. As of June 2003, there were 19 unpatched vulnerabilities in Microsoft's Internet Explorer. Many of these were serious and resulted in costly breaches and inconvenience to users.
• Some vulnerabilities cannot be fixed by patching. Patch management will not correct vulnerabilities caused by misconfiguration, such as default settings that allow access to systems that should be restricted.
• Vendors cannot develop a patch if they are unaware of the vulnerability. Most vulnerabilities are discovered by non-vendor third parties. Legitimate researchers follow responsible-disclosure guidelines, giving vendors time to develop patches before announcing vulnerabilities. Unfortunately, some parties release vulnerability information without informing vendors beforehand. In these cases, patch management is useless because it only can protect against vulnerabilities the vendor knows about well before the attackers.
• New hacker tools are reducing the patching window. These tools let attackers automatically reverse-engineer a patch to determine what was fixed and develop an exploit, sometimes within hours of patch release. Even using patch management, deployment speed is constrained by regression testing.
Foolish, as if the telcos could even possibly be cast as the 'good guys'. Wi-Fi was another technology...- Anonymous
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comment