Channel News and Analysis - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.
  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    Changing Patch Habits With Microsoft

    in Channel News and Analysis



    Article Rating:starstarstarstarstar / 0
    Article Views: 2992

    Microsoft's consistent release cycle is having a huge impact on enterprise security management, though worm writers are focusing on the regularity.

    Rate This Article:
    Add This Article To:

    In the year since Microsoft Corp. made its controversial decision to begin releasing patches on a monthly basis, the policy has had a profound effect on enterprise security—changing forever the way companies deploy updates and helping to hasten the end of the manual patching process.

    Administrators say the predictable patch cycle afforded to them by the monthly schedule has given them the ability to develop a plan for testing and deploying the fixes. Enterprises now know that on the second Tuesday of every month they will have a batch of updates delivered from Microsoft, which eliminates much of the fire drill mentality that surrounded the irregular releases of patches previously.

    So far, Microsoft officials say they are pleased with the overall effect of the monthly patch program.

    "It's going just as we'd hoped. Two years ago, we didn't have consumer mailers; we didn't have separate technical bulletins; we didn't have any of that stuff," said Stephen Toulouse, security program manager at the Microsoft Security Response Center, in Redmond, Wash. "It was a painful process. No one knew what was coming out. Customers get a higher patch quality now."

    In enterprise IT departments, the regular patch cycle has led to a number of changes. Many administrators say the change has given them time to test patches comprehensively and has upped their confidence in the updates they deploy.

    "The real issue is that you have to test patches, and how quickly we move on one is a function of the severity of the problem," said Adam Hansen, manager of security at Sonnenschein Nath & Rosenthal LLP, a Chicago law firm with more than 2,000 users in 11 offices. "I can plan for resource allocation better now. I plan on at least one critical patch every month, and I haven't been disappointed. And I can package the patches together once they're tested and push them out in a pack."

    For large distributed enterprises such as Sonnenschein, the increase in the number of patches in recent years made it nearly impossible to patch PCs manually. This has led to the rapid proliferation of automated patching and remediation tools such as Citadel Inc.'s Hercules and PatchLink Corp.'s Update, which enable administrators to identify vulnerable machines and push updates to them automatically.

    "I measured our compliance with manual patching once, and we had just 20 percent, and that was just the machines we knew about," said Hansen, whose company uses Hercules. "In a mobile work force, things just happen, so now we push anything that a user is missing and don't let them on the network until they're in compliance."

    But not all the changes have been positive. Security experts say crackers have taken notice of the monthly cycle and have begun timing their attacks to coincide with the release of the patches. In fact, managed security providers say that within hours of the release of a new set of patches from Microsoft, they see spikes in activity against whatever components or services the software company has just fixed.

    Worm writers, too, are taking advantage of the fact that Microsoft has been loath to release patches outside the regular cycle. Last month, the Bofra worm hit the Internet just two days after the public disclosure of a vulnerability in Internet Explorer. The worm appeared at the same time as Microsoft's November patch release, which did not include a fix for the IE flaw. Microsoft did, however, release an out-of-cycle patch for the vulnerability last week.

    Click here to read more about how Microsoft patched this vulnerability out of cycle.

    The vulnerability in IE was a buffer overrun in the way that the browser handles certain HTML tags and could allow an attacker to execute arbitrary code on a remote machine. In order to exploit the flaw, an attacker would simply need to entice a user to visit a malicious Web site that contained the exploit code.

    Patch work
    Changes since Microsoft went to monthly updates:
  • 320% increase in use of Windows Update
  • 400% increase in use of automatic updates
  • More than 100,000 SUS (Software Update Service) servers connecting to Microsoft monthly

    Check out eWEEK.com's Windows Center at http://windows.eweek.com for Microsoft and Windows news, views and analysis. Be sure to add our eWEEK.com Windows news feed to your RSS newsreader or My Yahoo page:  




    comments dic


     
     
    >>> More Channel News and Analysis Articles          >>> More By Dennis Fisher
     


  •  



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement