Home > Ask the Security Experts > Platform Security Questions & Answers > What tools are available to verify a patch's validity?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What tools are available to verify a patch's validity?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 04 September 2006
Do any patch management tools verify the content of the patches downloaded from Microsoft before they are tested and deployed? Can they be identified as true Microsoft files and not malicious files?

>
Before installing any patch, verify its source and integrity. This is typically done using a digital signature or some form of checksum. These verification techniques ensure the patch hasn't been modified since the signature was applied or since the checksum count was calculated. Signed patches also validate the patch's creator. Unfortunately, Microsoft occasionally releases unsigned code updates, and you may run into problems when using the automatic download and installation services of WSUS (Windows Server Update Services), Microsoft's patch management system for Windows Server 2000, Windows Server 2003 and Windows XP operating systems. If you set the "Warn but allow installation" policy object for unsigned code, Windows will prompt with a warning and halt the update procedure, waiting for confirmation that it's OK to install the update.

While Microsoft's documentation doesn't clarify whether WSUS performs digital signature or checksum counts prior to installation, its Baseline Security Analyzer (MBSA) examines file versions and checksums to verify the present files match with those released by Microsoft. If any of these files do not pass the test, MBSA will identify that the software update is not installed, or will flag the software update with a warning. It's important to note that this process can only be done after the patch has been installed. Interestingly enough, this product is licensed from Shavlik Technologies LLC, the makers of HFNetChkPro.

HFNetChkPro is a patch management program that validates file versions and checksums prior to deploying both Microsoft and non-Microsoft security patches. Its Basic Edition is designed for smaller organizations that don't require advanced patch management functionality like scheduled scans and email support.

PatchQuest is another automated patch management program that can distribute and manage security patches, hotfixes and updates across heterogeneous networks comprising Windows and Linux systems. It is a Web-based service that downloads patches, assesses patch authenticity and tests for functional correctness. The tool scans your network, identifies missing patches and software updates, distributes patches to vulnerable systems and keeps your systems up-to-date and free from vulnerabilities.

Should you receive a warning message that questions a patch's validity, you should fully investigate the digital certificate or checksum. Why you ask? In 2001, VeriSign Inc. issued two VeriSign Class 3 code-signing digital certificates to an individual who fraudulently claimed to be a Microsoft employee. The common name assigned to both certificates was "Microsoft Corporation," allowing the individual to sign executable content using keys that supposedly belonged to Microsoft. Thankfully, trust is defined on a certificate-by-certificate basis, rather than on the basis of the common name. Therefore, if a similar event occurred, a warning dialogue would be displayed before any of the signed content could be executed, even if the user had previously agreed to trust other certificates with the common name "Microsoft Corporation." The danger, of course, is that even a security-conscious user might agree to trust the bogus certificates and execute the content.

More information:

  • Use our step-by-step guide to successfully deploy a patch.
  • Get recommendations on proper patch management techniques.

  • BROWSE BY TAG
    Platform Security,   Application and Platform Security,   Enterprise Vulnerability Management,   Security Patch Management,   PKI and Digital Certificates,   Enterprise Identity and Access Management,   User Authentication Services,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Platform Security
    What patch management metrics does Project Quant use?
    Should developers create libraries of common cryptographic algorithms?
    How to secure USB ports on Windows machines
    What is the best database patch management process?
    What is an encryption collision?
    Is credit card tokenization a better option than encryption?
    Will a database anonymization implementation succeed?
    What are the Mac OS X Snow Leopard antivirus features?
    What are new and commonly used public-key cryptography algorithms?
    Should management processes change based on a patch release schedule?

    Security Patch Management
    Microsoft gives Internet Explorer a major security overhaul
    Information security book excerpts and reviews
    What patch management metrics does Project Quant use?
    Squad: Tokenization, Phishing and the Feds
    Should management processes change based on a patch release schedule?
    Should Windows Mobile updates come from Microsoft?
    Adobe updates ColdFusion, JRun, Flex
    Trusteer CEO criticizes Adobe, touts better patch deployments
    Patch management study shows IT taking significant risks
    Vulnerability mitigation study shows need for faster patching

    PKI and Digital Certificates
    How to encrypt passwords using network security certificates
    Best Authentication Products
    DoD urges less network anonymity, more PKI use
    Researchers to demonstrate new EV SSL man-in-the-middle hacks
    Portable security storage device could replace OTP devices
    What is most misunderstood about EV SSL certificates?
    VeriSign addresses MD5 flaw
    Rogue digital certificates strike blow to Internet security
    Can any firm or organization get a digital signature certificate?
    How to obtain a digital certificate for a server
    PKI and Digital Certificates Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    attack vector  (SearchSecurity.com)
    back door  (SearchSecurity.com)
    ethical worm  (SearchSecurity.com)
    Patch Tuesday  (SearchSecurity.com)
    zero-day exploit  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts