Home > Security News > Survey: Enterprises quicken patch processes
Security News:
EMAIL THIS

Survey: Enterprises quicken patch processes

By Anne Saita, News Director
03 Apr 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Patching used to be a real drag for Gabriel Selmi, the security designate for non-profit mental health services provider Advanced Behavioral Health Inc. of Middletown, Conn. When an update arrived, the network administrator and his tiny IT team would download it to a floppy disk and then walk around to about 50 machines. Or, they'd send out an e-mail with a link and ask the employees to do it.

"It was a complete nightmare for us, a lot of manual work," Selmi recalled.

Today, Advanced Behavioral Health's all-Windows shop now supports 200 local PCs at its headquarters and another 150 remote users that dial into the network using a VPN. But patching is no longer problematic, even with the window between a bulletin's release and exploit's circulation narrowing.

In 2004, and after months of serious comparison shopping, Selmi settled on a patch and vulnerability management service from Scottsdale, Arizona-based Patchlink Corp. that has eliminated much of the manual labor. But the patch landscape for many others remains riddled with land mines, and some enterprises are rushing to seal holes with unofficial patches or before properly testing sanctioned ones.

Proving that point, Patchlink on Monday released the results of a new customer survey that asked more than 250 CIOs, CSOs, IT managers and network administrators about their patch management practices. The results are based on information gathered during the company's 360 Security Conference in Tempe, Arizona, in February.

Among the results:

  • A majority (55%) believe software vendors should issue patches out of cycle when exploits are in the wild, with another 44% suggesting out-of-synch updates first be thoroughly tested.
  • Most companies roll out all newly available patches within five days (22%) or within one week to two months (28%). Only 8% roll out a new patch within 72 hours. However, when it's a critical patch, 40% will apply it immediately, while 24% will deploy a fix within 2 to 5 days. Another 16% will do so within two months, and the remaining 18% have no set timeframe.
  • Because Patchlink tests all patches prior to releasing them to customers, it's not too surprising that a quarter of respondents spent less than an hour testing patches on their own. About the same number tested for one to five hours, while less than 5% took five to 10 hours. Twenty percent took a day, while almost 23% took longer.
  • How much is too much
    Patch cycles remain controversial, particularly among users of major vendors like Microsoft and Oracle Corp. Both have been accused of leaving customers at risk by delaying the release of critical updates. While the two vendors staunchly defend their actions, security researchers have long criticized them for not going public soon enough when serious flaws in their software programs are discovered. Increasingly, others are issuing independent workarounds or patches ahead of a vendor's official fix.
    Related items

    Fake BBC e-mails seek to exploit IE flaw

    Third-party patches available for IE flaws

    In December, when malware writers found a way to embed malicious code in Web images using the Windows Meta File flaw, reputable organizations like the SANS Internet Storm Center encouraged security pros to download researcher Ilfak Guilfanov's API block in the absence of anything official out of Redmond.

    Then, just last week vendors eEye Digital Inc. and Determina Inc., both located in California, issued actual binary patches to the DLL for the createTextRange flaw in Internet Explorer, which Microsoft has yet to patch.

    "They may be from reputable sources, but if they aren't released by Microsoft and approved by Patchlink… We don't bother with third-party patches," Selmi said. The network admin said such faith in third parties remains dangerous, "and I don't see that changing any time soon," he said.

    Selmi is not alone, according to the Patchlink survey. Seventy percent passed on Guilfanov's solution and waited until Patchlink had vetted the approved Microsoft WMF patch, which ended up being released ahead of Patch Tuesday due to public pressure.

    Chris Andrews, vice president of security technologies for Patchlink, said those enterprise IT shops still tending to patches themselves should be especially suspicious of fixes that arrive in unsolicited e-mails.

    "There are a lot of folks getting involved in this process, with security companies starting to put out temporary fixes," Andrews said. "The last thing you want to do is get a patch from an untrusted source. We've all seen the e-mails claiming to have new fixes for new Microsoft issues and suddenly your users are trying to take security into their own hands and next thing you know you've got spyware all over your network."

    He recommended a staged approach. Test the patch with a small sample initially (off- and then online) and if successful, move to a pilot group and then the general network population. "You need to take a cautious approach and not just blast the patch straight out, you could run into problems. It's always best to test on a small number of representative machines first."

    Tags: Security Patch ManagementVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Security Patch Management
    Squad: Tokenization, Phishing and the Feds
    Should management processes change based on a patch release schedule?
    Should Windows Mobile updates come from Microsoft?
    Adobe updates ColdFusion, JRun, Flex
    Trusteer CEO criticizes Adobe, touts better patch deployments
    Patch management study shows IT taking significant risks
    Vulnerability mitigation study shows need for faster patching
    Microsoft to issue security report card, new tool at Black Hat
    How to manage patches for Adobe
    When is it suitable to remove Java updates?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    attack vector  (SearchSecurity.com)
    back door  (SearchSecurity.com)
    ethical worm  (SearchSecurity.com)
    Patch Tuesday  (SearchSecurity.com)
    zero-day exploit  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts