Defend against patch-based exploits, warns Sans

By Tom Espiner, ZDNet UK
Wednesday, May 07, 2008 10:35 AM

Security training organization the Sans Institute claims centralized patch management can be used to counter the threat of automated, patch-based exploit generation.

The advice, published on Monday, follows the release of research from the University of California at Berkeley, University of Pittsburgh and Carnegie Mellon University that maintained that exploits for vulnerabilities in code can be reverse-engineered from patches and generated automatically.

The paper recommended that software patches be distributed in encrypted form, to reduce the amount of time attackers have to reverse-engineer the patch. However, Sans contributor John Bambenek criticized this approach and said that the major problem with patching was the time it took to reboot systems once a patch has been applied.

"The problem with this is that the delay from the time of releasing the patch is not caused from the rolling cycle of downloads but from the need to reboot systems after a patch is applied (most of the time)," wrote Bambenek. "In short, a system may still have the key to decrypt a patch but it would not be applied until either the user rebooted the machine or at some default time when a reboot is acceptable (ie, 3am)."

Instead, Bambenek called on systems managers--"the people in the trenches"--to centrally manage patch distribution and other defence measures such as hot fixes and kill bits--Microsoft workarounds to stop unexpected ActiveX execution in Internet Explorer.

"If we get out hot fixes, registry changes, kill bits or any other defence, centralized configuration management allows for the quick deployment of these minor protective changes that will allow you to 'limp along' until a patch can be applied," wrote Bambenek.

However, those managers deploying configuration and patch-management products should be aware that any patch-management application becomes the "absolute most important system in your environment, even more important than those that house trade secrets".

"A configuration-management system becomes a 'single point of 0wnership' that allows an attacker to take direct control over not one machine but an entire organization, whole and entire," wrote Bambenek. "Protect the keys to the kingdom."

Bambenek also called on software manufacturers to bring out patches that do not require a reboot and for the security researcher community to speedily bring out any necessary workarounds.

"Some patches will require reboots and there will be no way around that. We need to find defences to allow people to protect themselves in the meantime," wrote Bambenek.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Mainsoft: Opening options for Java, .NET developers

Java

Mainsoft provides tools for running .NET code on the Java platform.


Read more »


Tags

  1. against
  2. antivirus
  3. asian
  4. attacks
  5. blame
  6. by
  7. critical
  8. cyber
  9. data
  10. flaw
  11. flaws
  12. google
  13. govt
  14. hit
  15. hp
  16. malware
  17. microsoft
  18. online
  19. over
  20. security
  21. software
  22. symantec
  23. threats
  24. uk
  25. under
  26. update
  27. updates
  28. us
  29. warns
  30. web
 
Increase performance with eco-technology innovations
Simplify your infrastructure and unify management, while lowering power and cooling costs of your datacenter.
» Maximum flexibility with powerful blade technolgy
» Bring new services and applications online faster
» Lower energy use and cost
Oracle SOA Business Software Centre
Many companies are recognizing the need to adopt standards in their efforts to build service-oriented applications.
Secure the "Next-Gen SOA Infrastructure" & "Bringing SOA Value Patterns to Life" whitepapers here

» Visit the Power Center

Up close and personal with a merger

Blog thumbnail

What can you get for 13.9 billion buckaroos? For Hewlett-Packard, US$13.9 billion would allow you to buy your way into becoming the second biggest IT services company in the industry...... by Eileen Yu

Read more »