Home > Security News > Third-party patching: Prudent or perilous?
Security News:
EMAIL THIS

Third-party patching: Prudent or perilous?

By Bill Brenner, Senior News Writer
28 Aug 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Third-party patching, a hot topic in recent months given the increased prevalence of zero-day flaws, was among the issues dissected at the recent Black Hat USA 2006 conference in Las Vegas.

In one presentation, Alexander Sotirov, a reverse engineer on the security research team at Redwood City, Calif.-based vulnerability protection firm Determina Inc., said third-party patching provides another security option for IT shops that need to block exploits before an official patch is developed, and that those patches are easy to uninstall after an official patch is released.

Sotirov did acknowledge that there are some disadvantages to third-party patching: There's limited support for multiple operating system versions and languages, and some vulnerabilities require extensive changes or redesign of the affected application and simply can't be hotpatched.

While some organizations might not hesitate to use a third-party fix if a threat is dire enough, IT professionals interviewed by SearchSecurity.com after Black Hat said they would never deploy one in their own environments.

"Third-party patching is potentially another area of vulnerability in my opinion," said Jessica Lynne Verzi, information security manager for ESL Federal Credit Union, a financial institution with 550 employees, 17 branches and numerous ATM locations in the Rochester, N.Y.-area. "It's very reactive and very dangerous to install one."

Third-party patches were released for two different Microsoft threats earlier this year.

In January, Russian programmer Ilfak Guilfanov made a patch available to address the widely-exploited Windows Meta File glitch Microsoft ultimately patched.

In March, Determina and Aliso Viejo, Calif.-based eEye Digital Security Inc. released third-party patches for the createTextRange flaw involving Internet Explorer, which Microsoft patched in its April security bulletins.

In both cases, reaction was mixed in the information security community. With WMF and, to a lesser extent, createTextRange being widely exploited, some argued a third-party fix was better than nothing. Others warned that patches can never be fully trusted unless they come straight from the vendor of the affected product.

Verzi didn't lose any sleep over those threats because she said ESL Federal Credit Union utilizes a variety of security measures that would make it very difficult for attackers to successfully target an organization using those flaws.

Verzi said enterprises that practice so-called defense in-depth have the necessary security in place to mitigate threats that exploit zero-day flaws and can therefore afford to wait for the official patch.

Craig Hunter, IT manager for the City of North Vancouver, said organizations that have such a security program can afford to wait a few weeks for an official patch.

"Third-party patching is more trouble than it's worth," he said, agreeing with Verzi that it can potentially introduce more vulnerabilities to the network. "Using a mitigation strategy like blocking certain ports or shutting certain programs is the better solution. The user may have to go without a feature for a week, but it's better than taking a risk with a third-party fix that you then have to go and uninstall before installing the real patch."

Keith Gosselin, IT officer for Biddeford Savings Bank in Biddeford, Maine, is also concerned about how his applications would work if he ever tried to install a third-party patch.

"Applications are so finicky, I'd be worried about an application exploding in my face," said Gosselin, whose company has 70 employees and three bank branches, with a fourth opening in September.

Like the others, Gosselin preaches the virtues of a well-rounded defense, and said he makes a point of educating employees on the potential consequences of their computing habits.

"I do spend a lot of time keeping track of zero-day threats so I'm aware of out-of-cycle fixes," he said. "I want to know when there's an exploit so I can email users and warn them to be careful."

Black Hat USA 2006

Check out SearchSecurity.com's special coverage of Black Hat USA 2006 as reporters from SearchSecurity.com and Information Security magazine post the latest news and tidbits from Las Vegas.
For example, during the recent PowerPoint threat, he sent out an email warning employees not to open PowerPoint attachments unless they are expecting one from a trusted source.

He supplements urgent warnings with routine emails about every other month that ask people to be careful when opening attachments. "If you get a file from someone you know that you weren't expecting, I tell them to call that person before opening the attachment," he said.

With these practices in place, he said, there's never a need to use a third-party patch.

To those who argue that patches can't be trusted unless they come from the vendor of the affected program, Determina's Sotirov told his Black Hat audience, "Most software vendors have a long record of shipping vulnerable software. If we trust them, there is no reason not to trust a third-party patch from a well-known security expert or a security company."

Furthermore, he said, "Third-party patches are ideal for situations where the risk of a system compromise outweighs the risk of interoperability issues."

Tags: Security Patch ManagementEnterprise Risk Management: Metrics and AssessmentsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Security Patch Management
Squad: Tokenization, Phishing and the Feds
Should management processes change based on a patch release schedule?
Should Windows Mobile updates come from Microsoft?
Adobe updates ColdFusion, JRun, Flex
Trusteer CEO criticizes Adobe, touts better patch deployments
Patch management study shows IT taking significant risks
Vulnerability mitigation study shows need for faster patching
Microsoft to issue security report card, new tool at Black Hat
How to manage patches for Adobe
When is it suitable to remove Java updates?

Enterprise Risk Management: Metrics and Assessments
How to avoid Internet liability lawsuits
Bruce Jones: Report Security and Risk Metrics in a Business-Friendly Way
Bernie Rominski: Communicate Effectively with Management about Risk
Best Policy and Risk Management Products
Monitoring program data and internal controls for risk management
Risk management strategy for an information technology solution provider
Align your data protection efforts with GRC
The basics of enterprise GRC project management
RSA council addresses growing security risks in the cloud
How to write a risk methodology that blends business, security needs
Enterprise Risk Management: Metrics and Assessments Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
attack vector  (SearchSecurity.com)
back door  (SearchSecurity.com)
ethical worm  (SearchSecurity.com)
Patch Tuesday  (SearchSecurity.com)
zero-day exploit  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts