- Nokia's new N97 vs. the iPhone
- 10 Microsoft research projects
- Hard to get justice in MySpace case
- Smartphone smackdown: Storm vs. iPhone
- Apple removes antivirus support page
Internet Security Systems is readying technology it says could benefit companies fed up with current patch management techniques.
More precisely, ISS will enable its vulnerability-assessment scanner to gang up with its network- and host-based intrusion-detection systems (IDS) to stop newly discovered attacks or worms that could damage unprotected servers or desktops on enterprise networks.
ISS CTO Chris Klaus calls the idea "virtual patching" because it could eliminate the need to immediately apply server or desktop software patches, which are often required to combat new attacks that exploit software holes. Instead of having to rush to patch the application or operating system software to stop a fast-moving worm from taking over vulnerable systems, ISS would be able to have its IDS ready to take certain steps to stop specific attacks aimed at the target machine.
"Patching is unattainable. There's no Fortune 1000 company doing it across all its systems," contends Klaus, who points out that sometimes vendors stop supplying patches for their legacy products. "For instance, Microsoft is no longer supporting patching for Windows NT."
Next month ISS will add the virtual patching capability to its vulnerability-assessment tool, Internet Scanner 7.0, which runs on Windows 2000.
Continuously updated with new attack information as it becomes known, Internet Scanner will examine Web servers, firewalls, operating systems, routers, switches, mails servers and other applications to determine where a variety of weaknesses reside. The product also will perform network discovery to locate network resources.
Internet Scanner will no longer simply be a stand-alone tool, but will be able to take commands from the ISS management console, SiteProtector. Companies could then perform a scan when a new vulnerability or threat was identified, to see which machines could be hit. Then, based on the network manager's decision, SiteProtector would be able to instruct the ISS network-based sensor, RealSecure Network 7.0, or the host-based IDS, RealSecure Server 7.0 and RealSecure Desktop 7.0, to take certain steps. The host-based IDS could block access, based on a specific check or signature.
Since traditional "passive" IDS products aren't in-line devices that can block large traffic streams, RealSecure Network 7.0 would be limited to instructing the firewall to block the attack through a process called shunning, or alternatively, terminating a session with TCP re-sets.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment