I'm hearing more and more about fake patches coming from supposedly reputable programs -- including Google Chrome...
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
and Java. How do these attacks work and what are some best practices I can instill to keep my users from installing fake updates?
Time and time again I have said that enterprises should turn on the auto-update feature if they are not going to actively manage any piece of software. However, this recommendation relies on software vendors using secure methods to push out updates and patches to their customers.
While it is a reasonable expectation from Microsoft, Adobe and other similar companies, software vendors without robust information security as part their software development lifecycle might not have sufficient protections in place to protect their customers. This process requires creating patches that can be verified to not have been modified and to have come from the legitimate source and then validated on the client system. Unfortunately, regardless of a company's precautions, there are instances of issues. Even Microsoft's Windows Update was subverted in the Flame malware attack, in which the malware used a fraudulent certificate to send out fake Windows update patches.
However, in the aforementioned cases of updates for Chrome and Java, the fake patches were not the result of attacking the auto-update capabilities; rather they used social engineering to trick users into installing malicious "updates." These updates used company logos and terminology to trick users into believing that the update was legitimately from a trusted vendor.
To prevent your employees from falling victim to such social engineering attacks, enterprises could prohibit users from installing software and software updates on corporate devices and have the IT department take care of all patching. Additional security measures organizations could implement include using a Web browser that checks against a blacklist for malicious downloads, employing a network-based antimalware appliance, or adopting a host-based security tool that can identify fake patches before they are installed and thus minimize the chances of a user being tricked by a fake update.
Ask the Expert!
Perplexed about enterprise security? Send Nick Lewis your questions today! (All questions are anonymous.)
Dig Deeper on Malware, virus, Trojan and spyware protection and removal
Related Q&A from Nick Lewis
A keylogging flaw found its way into dozens of Hewlett Packard laptops. Nick Lewis explains how the HP keylogger works and what can be done about it.continue reading
Can Structured Threat Information eXpression improve threat intelligence sharing? Nick Lewis breaks down the evolution of the STIX security framework.continue reading
A new type of WordPress malware, WP-Base-SEO, disguises itself as an SEO plug-in that opens backdoors. Nick Lewis explains how it works and how to ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.