![]() |
Patch
Now, Not Later
Never before have there been so many potential costly threats to your business information. Protect your business by staying up-to-date with patches for all your software programs. Introduction 'A fix' Patch updates only modify the portion of the program code necessary to correct or enhance functionality. These corrections and enhancements range from fixing bugs, to replacing graphics, to improving the usability or performance of a previous version of software. Sometimes software vendors release patches to eliminate functionality or to prevent users from performing a certain activity. This article addresses patching for security purposes. The Need to Patch
Web application risks - Web applications allow users to share, create, or modify content through a Web browser. While convenient and efficient, they are prone to vulnerabilities. Web application vulnerabilities are worrisome as they can expose information publicly over the Internet. They may allow access to confidential information from databases without compromising any servers. They may also allow an attacker to circumvent traditional perimeter security measures, such as firewalls, and are particularly dangerous because they could compromise an entire network by gaining access through a single local system. Zombies - So-called zombie computers (or bot networks) are clusters of compromised computers on which attackers have installed software, allowing them remote control. Zombies are constantly searching for new machines to infect. Unpatched vulnerabilities are the usual culprits. Symantec feels that the security threat from these attacks will only worsen, especially in financial terms. Increasingly, zombie computers are being used for financial gain. Symantec expects this trend to escalate, as the diverse means of acquiring new zombies become more prevalent. Vulnerability window - In the last six months of 2004, according to Symantec research, the average time between vulnerability discovery and the time it took to create an exploit was 6.4 days. As demonstrated by the recent Zotob virus, the vulnerability window is shrinking. This trend is precisely why systems must be patched immediately. Finding Patches
Most programs allow you to update patches automatically. However, patches are not perfect. Some have caused damage. Security experts suggest regularly updating security programs, such as antivirus programs or firewalls. If you are using a patch management tool, know exactly what the tool is patching. Even the best patch management tool might not automatically download every patch, especially for an obscure application. Patch management tools may download patches, but these tools may not actually deploy them for you. You will still need to devote time to manually approving updates. Remember, just as your system needs to be updated regularly, so too does your patching tool. A Thorough Security Policy Here are a few suggestions that can serve as stepping-stones for including patching in your overall security policy:
|