Feeds

Security patch approach is failing

If MS Web admins can't keep up to date

  • alert
  • submit to reddit

Top 5 reasons to deploy VMware with Tegile

A noted security expert has said current security practices are too reliant on expecting users to apply patches and has suggested better monitoring might lead to more robust security.

Bruce Schneier, chief technology officer of Counterpane Internet Security, said the outbreak of the Code Red Worm, which targets vulnerable IIS Web servers, shows that "the patch treadmill doesn't work".

Schneier argues that when even Microsoft's Web admins can't keep up to date with patches (one of the many sites defaced by the worm was the Windows Update page) it shows the approach is failing. He said the patching approach doesn't take into account human weaknesses or that patches sometimes break other parts of a network or sometimes require for critical systems to be taken offline in order to be applied.

These are good points, but can the defenders of networks come up with a better approach (and preferably one that doesn't blame the victim for security breaches)?

Schneier certainly thinks so and advocates wider use of security monitoring as a means to fill the security gaps.

"If you are monitoring your network carefully enough, you'll catch a hacker regardless of what vulnerability he exploited to gain access," said Schneier.

"Monitoring makes a network less dependent on keeping patches up to date; it's a process that provides security even in the face of ever-present vulnerabilities, uninstalled patches, and imperfect products."

Schneier admitted that vigilant monitoring does not "solve" computer security, but his argument that is a much realistic way of providing resilient security is worth considering.

The reactive nature of monitoring can give attackers time to do some serious damage, so we can't see the approach will take us away from the need to apply security patches altogether, but it has the potential to reduce risk.

Firewalls alone don't provide adequate defences, particularly against something like Code Red, which is a pre-programmed worm that unleashes a distributed attack against a predetermined target, and intrusion detection systems are generally only as good as their latest attack signatures.

We can't see that monitoring would be much good in isolation but it might well be successful at picking up problems more effectively and making Internet security less fragile. After all, it can hardly hurt... ®

External Links

CERT advisory on Code Red with links to Microsoft's patches

Related Stories

Internet survives Code Red
Code Red bug hits Microsoft security update site
IIS worm made to packet Whitehouse.gov
IIS buffer-overrun attack has been scripted
MS confronts another IIS system-level hole
Yet another IIS exploit reported
Microsoft IIS hole gives System-level access
Security patch distribution - it's Trojan time

Internet Security Threat Report 2014

More from The Register

next story
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Home Depot ignored staff warnings of security fail laundry list
'Just use cash', former security staffer warns friends
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Freenode IRC users told to change passwords after securo-breach
Miscreants probably got in, you guys know the drill by now
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
BitTorrent's peer-to-peer chat app Bleep goes live as public alpha
A good day for privacy as invisble.im also reveals its approach to untraceable chats
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.