ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Defend against patch-based exploits, warns Sans

Tom Espiner ZDNet.co.uk

Published: 06 May 2008 16:51 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security training organisation the Sans Institute claims centralised patch management can be used to counter the threat of automated, patch-based exploit generation.

The advice, published on Monday, follows the release of research from the University of California at Berkeley, University of Pittsburgh and Carnegie Mellon University that maintains that exploits for vulnerabilities in code can be reverse-engineered from patches and generated automatically.

The paper recommended that software patches be distributed in encrypted form, to reduce the amount of time attackers have to reverse-engineer the patch. However, Sans contributor John Bambenek criticised this approach, saying that the major problem with patching was the time it takes to reboot systems once a patch has been applied.

"The problem with this is that the delay from the time of releasing the patch is not caused from the rolling cycle of downloads but from the need to reboot systems after a patch is applied (most of the time)," wrote Bambenek. "In short, a system may still have the key to decrypt a patch but it would not be applied until either the user rebooted the machine or at some default time when a reboot is acceptable (ie, 3am)."

Instead, Bambenek called on systems managers — "the people in the trenches" — to centrally manage patch distribution and other defence measures such as hot fixes and kill bits — Microsoft workarounds to stop unexpected ActiveX execution in Internet Explorer.

Read this

Q&A
Q&A: The Russian approach to tackling data breaches

Kaspersky Lab co-founder Natalya Kaspersky aims to move beyond the consumer antivirus business by helping companies guard against data breaches...

Read more +

"If we get out hot fixes, registry changes, kill bits or any other defence, centralised configuration management allows for the quick deployment of these minor protective changes that will allow you to 'limp along' until a patch can be applied," wrote Bambenek.

However, those managers deploying configuration and patch-management products should be aware that any patch-management application becomes the "absolute most important system in your environment, even more important than those that house trade secrets".

"A configuration-management system becomes a 'single point of 0wnership' that allows an attacker to take direct control over not one machine but an entire organisation, whole and entire," wrote Bambenek. "Protect the keys to the kingdom."

Bambenek also called on software manufacturers to bring out patches that don't require a reboot and for the security researcher community to speedily bring out any necessary workarounds.

"Some patches will require reboots and there will be no way around that. We need to find defences to allow people to protect themselves in the meantime," wrote Bambenek.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
1 out of 1 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Visual Basic/SQL Server Support/Development - East London - 35k!

You will also be responsible for performing day to day maintenance and patch management and general application support. An experienced Visual Basic ...

Network Engineer

Duties include network monitoring, patch management, switch and router management and increasingly considering the convergence of the voice and data ...

Messaging Engineer (Exchange 2003/07, OCS/LCS) BANKING

Main functions of the role are troubleshooting & resolving cross platform message flow related issues, problem resolution & estate & patch ...

Sentry Posts Blog

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Google sponsors open source security p...

Google has announced it is to sponsor oCERT, an open source computer emergency response team. In a blog post on Monday, Google security engineer Will Drewry said that one of the... More

Post a comment

Indian officials accuse China of cyber...

China is actively engaged in mapping India's computer networks, according to the Times of India. China is mounting "almost daily" attacks against Indian Government computer systems,... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation