Printer Friendly
The Free Library
14,550,258 articles and books
Member login
User name  
Password 
 
Join us Forgot password?

Automated patching: an easier approach to managing your network security.


Patch management The installation of patches from a software vendor onto an organization's computers. Patching thousands of PCs and servers is a major issue. A patch should be applied to test machines first before deployment, and the testing environments must represent all the users' PCs with their unique  is an essential administration task within today's busy IT networks with the constant threat of new security bugs A security bug is a software bug that benefits someone other than intended beneficiaries in the intended ways.

Security bugs introduce security vulnerabilities by compromising one or more of:
  • Authentication of users and other entities
. Some companies will wait for an attack before taking necessary action to protect themselves from further threat whilst others consider patching as often as possible. Patching networks consists of scanning machines for any missing patches and deploying those patches as soon as they become available. Using an automated au·to·mate  
v. au·to·mat·ed, au·to·mat·ing, au·to·mates

v.tr.
1. To convert to automatic operation: automate a factory.

2.
 patch management solution is the best way to avoid problems when a security threat/bug is issued from Microsoft (Microsoft Corporation, Redmond, WA, www.microsoft.com) The most successful and influential software company. Microsoft's software and Intel's hardware pioneered the PC and revolutionized the computer industry.  on the first Tuesday First Tuesday is a networking forum for technology entrepreneurs, companies seeking venture capital, investors and related service providers. Founded in 1998, First Tuesday now has 38,000 members and the 10 branches across Europe host meetings on the first Tuesday every month.  of each month.

Saving network bandwidth and being able to deploy patches from a remote source is also a major benefit to organisations today.

Determining what to patch and when is one of the most problematic issues facing enterprises. An expert panel at an Information Security Decisions conference in Chicago, USA said the ever-diminishing window of time between vulnerability's announcement and an exploit's release makes it crucial to analyze and patch the areas most likely to be attacked first.

One example of a security breach was the virus 'Code Red" which infected in·fect  
tr.v. in·fect·ed, in·fect·ing, in·fects
1. To contaminate with a pathogenic microorganism or agent.

2. To communicate a pathogen or disease to.

3. To invade and produce infection in.
 over 250,000 systems within just nine hours of its discovery. The original CodeRed caused a Denial of Service A condition in which a system can no longer respond to normal requests. See denial of service attack.  (DOS) attack on the White House Web server. CodeRed II was different in that it allowed its creator to have full remote access to the Web server.

I always urge folks to rate the patches themselves. Patches are often rated arbitrary. Ask yourself whether a 'criticap' patch is critical to your organization? Look at the risk involved. For example, a denial of service is ranked as a low-level threat by Microsoft, but could be critical to an online bank, If a network is not patched in time before an attack occurs than the costs involved can be enormous. For example, the loss of production and sales and the cost to clean the incident up can be phenomenal.

Eric Schultze, Shavlik Technologies
COPYRIGHT 2005 A.P. Publications Ltd.
No portion of this article can be reproduced without the express written permission from the copyright holder.
Copyright 2005, Gale Group. All rights reserved. Gale Group is a Thomson Corporation Company.

 Reader Opinion

Title:

Comment:



 

Article Details
Printer friendly Cite/link Email Feedback
Title Annotation:DATABASE & NETWORK JOURNAL INTELLIGENCE
Author:Schultze, Eric
Publication:Database and Network Journal
Geographic Code:1USA
Date:Apr 1, 2005
Words:323
Previous Article:The demise of traditional perimeter defences.(DATABASE & NETWORK JOURNAL INTELLIGENCE)
Next Article:The network poltergeist.(DATABASE & NETWORK JOURNAL INTELLIGENCE)(Grayware)
Topics:



Related Articles
NETSEC LAUNCHES NEW INTEL SERVICE TO DELIVER REAL-TIME VULNERABILITY REPORTING.
Merant improves change management for Oracle APPS.(PVCS Change Manager for Oracle 3.7)(Product Announcement)
Winning the cybersecurity war: "he who excels at resolving difficulties does so before they arise. He who excels in conquering his enemies triumphs...
St. Bernard Software Announces Next-Generation Patch Management Solution; UpdateEXPERT(R) Premium Offers New Patching Capabilities Plus Added...
Network Intelligence Selected to Present The Value of Windows Event Logging at Microsoft TechNet Webcast; Webcast Demonstrates Superior Agent-Free...
Strategic Technology Partner Program Broadens Ecosystem for Innovative Network Access Control Solution.
PacketMotion Strengthens Internal Network Security Solution with Simplified Data Management.
Altiris to Provide Integrated Management and Remediation of Critical PC and Data Security Threats.
Independent Research Firm Cites Data Center Automation as Critical Requirement for Managing Virtual Servers; ''Data Center Automation Software Can...
You can't manage what you can't see!(Infosecurity Europe 2006: 25th-27th April 2006, Olympia, London.)

Terms of use | Copyright © 2009 Farlex, Inc. | Feedback | For webmasters | Submit articles