I'm hearing more and more about fake patches coming from supposedly reputable programs -- including Google Chrome...
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
and Java. How do these attacks work and what are some best practices I can instill to keep my users from installing fake updates?
Time and time again I have said that enterprises should turn on the auto-update feature if they are not going to actively manage any piece of software. However, this recommendation relies on software vendors using secure methods to push out updates and patches to their customers.
While it is a reasonable expectation from Microsoft, Adobe and other similar companies, software vendors without robust information security as part their software development lifecycle might not have sufficient protections in place to protect their customers. This process requires creating patches that can be verified to not have been modified and to have come from the legitimate source and then validated on the client system. Unfortunately, regardless of a company's precautions, there are instances of issues. Even Microsoft's Windows Update was subverted in the Flame malware attack, in which the malware used a fraudulent certificate to send out fake Windows update patches.
However, in the aforementioned cases of updates for Chrome and Java, the fake patches were not the result of attacking the auto-update capabilities; rather they used social engineering to trick users into installing malicious "updates." These updates used company logos and terminology to trick users into believing that the update was legitimately from a trusted vendor.
To prevent your employees from falling victim to such social engineering attacks, enterprises could prohibit users from installing software and software updates on corporate devices and have the IT department take care of all patching. Additional security measures organizations could implement include using a Web browser that checks against a blacklist for malicious downloads, employing a network-based antimalware appliance, or adopting a host-based security tool that can identify fake patches before they are installed and thus minimize the chances of a user being tricked by a fake update.
Ask the Expert!
Perplexed about enterprise security? Send Nick Lewis your questions today! (All questions are anonymous.)
Dig Deeper on Malware, virus, Trojan and spyware protection and removal
Related Q&A from Nick Lewis
The Fruitfly Mac malware has decades-old code, but has been conducting surveillance attacks for over two years without detection. Expert Nick Lewis ...continue reading
A Gmail phishing attack brought users to fake login pages designed to look like Google's. Expert Nick Lewis explains how users can prevent similar ...continue reading
A HummingBad malware variant, HummingWhale, was discovered being spread through 20 apps on the Google Play Store. Expert Nick Lewis explains the ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.