Security - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.
  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    Is 'Patch Tuesday' Dead?

    in Security



    Article Rating:starstarstarstarstar / 2
    Article Views: 15198

      Table of Contents:
    1. Is 'Patch Tuesday' Dead?
    2. Hackers' Window of Opportunity

    After five years of Microsoft releasing patches on the second Tuesday of the month, there’s some evidence that hackers are trying to game the release cycle to their advantage. Is it time for Microsoft to change its pattern?

    Rate This Article:
    Add This Article To:

    Is 'Patch Tuesday' Dead? - Hackers' Window of Opportunity


    ( Page 2 of 2 )

     

    Microsoft is aware of the window of opportunity between Patch Tuesday and the actual deployment of patches in production environments. For years, the recommended best practice for patching called for security teams to conduct regression testing in nonproduction environments before rolling out to production machines. The lag time created by testing creates the exploitation window of opportunity.

    Microsoft even acknowledges the potential for hackers to keep exploits in reserve to see what fixes are released on Patch Tuesday. However, it believes both the process and layers of protection built into the Patch Tuesday release cycle provide adequate protection against many exploits. The first line of defense is the Active Protection Program, a collaborative effort by Microsoft and 22 partners to provide intermediary workarounds and shields against the exploitation of vulnerabilities before new patches are deployed.

    “If you look at Patch Tuesday, we provide means to protect and information to prioritize the patch deployment,” says Mike Reavey, director of the Microsoft Security Response Center, the unit charged with triaging Microsoft vulnerabilities and creating patches. “The window of vulnerability is what Active Protection was designed for. While users are doing their regression testing of the new patch, they’re being protected by the 22 vendors in the program.”

    Additionally, automatic updates embedded in Windows and other Microsoft applications enable Microsoft to transparently deploy patches—which is particularly useful for home and small-business users that don’t follow security bulletins or have dedicated administrative support.

    When all else fails, Reavey says Microsoft will deploy a patch outside the regular Patch Tuesday cycle. While Microsoft released three out-of-band patches in 2008, it has only broken the Patch Tuesday cycle eight times in the last five years, Reavey says.

    “The customers I’ve talked with still appreciate the predictable cycle,” Reavey says. “Having partners that provide protection and releasing more information keep [Patch Tuesday] relevant.”

    Few people will dispute the utility and effectiveness of Patch Tuesday. While Microsoft is releasing only one patch this month, software rival Oracle is unleashing a tsunami of 41 patches for numerous applications. But should Microsoft consider a little less predictable patch release process? Reavey says no, but others say it should be on the table.

    “Microsoft maybe should start thinking about some additional randomization; it might be helpful," FishNet’s Shilts says. “It’s probably better to have regularity and have a process in place to deploy patches as they come out.”

     




     
     
    >>> More Security Articles          >>> More By Lawrence Walsh
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement