Advertisement
Promo

Security threats Toolkit

Defend against patch-based exploits, warns Sans

Tom Espiner ZDNet.co.uk

Published: 06 May 2008 16:51 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security training organisation the Sans Institute claims centralised patch management can be used to counter the threat of automated, patch-based exploit generation.

The advice, published on Monday, follows the release of research from the University of California at Berkeley, University of Pittsburgh and Carnegie Mellon University that maintains that exploits for vulnerabilities in code can be reverse-engineered from patches and generated automatically.

The paper recommended that software patches be distributed in encrypted form, to reduce the amount of time attackers have to reverse-engineer the patch. However, Sans contributor John Bambenek criticised this approach, saying that the major problem with patching was the time it takes to reboot systems once a patch has been applied.

"The problem with this is that the delay from the time of releasing the patch is not caused from the rolling cycle of downloads but from the need to reboot systems after a patch is applied (most of the time)," wrote Bambenek. "In short, a system may still have the key to decrypt a patch but it would not be applied until either the user rebooted the machine or at some default time when a reboot is acceptable (ie, 3am)."

Instead, Bambenek called on systems managers — "the people in the trenches" — to centrally manage patch distribution and other defence measures such as hot fixes and kill bits — Microsoft workarounds to stop unexpected ActiveX execution in Internet Explorer.

Read this

Q&A
Q&A: The Russian approach to tackling data breaches

Kaspersky Lab co-founder Natalya Kaspersky aims to move beyond the consumer antivirus business by helping companies guard against data breaches...

Read more +

"If we get out hot fixes, registry changes, kill bits or any other defence, centralised configuration management allows for the quick deployment of these minor protective changes that will allow you to 'limp along' until a patch can be applied," wrote Bambenek.

However, those managers deploying configuration and patch-management products should be aware that any patch-management application becomes the "absolute most important system in your environment, even more important than those that house trade secrets".

"A configuration-management system becomes a 'single point of 0wnership' that allows an attacker to take direct control over not one machine but an entire organisation, whole and entire," wrote Bambenek. "Protect the keys to the kingdom."

Bambenek also called on software manufacturers to bring out patches that don't require a reboot and for the security researcher community to speedily bring out any necessary workarounds.

"Some patches will require reboots and there will be no way around that. We need to find defences to allow people to protect themselves in the meantime," wrote Bambenek.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
1 out of 1 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters