Patching: because “Whoever is the most flexible, wins”
Posted: Friday, December 1, 2017
With cybercrime growing ever more prevalent and hackers even resorting to hacking one another (no, really – read Sophos’ security blog[i]) it is more important than ever to consider the best ways to keep your data secure regardless of the size of your network – even if you are the extent of your network.
Ransomware is now mainstream news and with the Cyberaware ad campaign[ii] in full force across UK TV screens, there are a few security imperatives on which everyone agrees (including the ex-chief of the FBI, James Comey). These are: passwords, patching, back-up and end-user training.
If you read my last security blog, you should already have your password locked-down by now, so this week we will progress to ‘patching’. Then, later in the series, we’ll be covering back-ups and how to boost your end-user knowledge.
The importance of patch management
What is patch management? Well, the US National Institute of Standards and Technology (NIST) defines it as follows: “patch management is the process for identifying, acquiring, installing, and verifying patches for products and systems.”
In the UK, we have GDPR coming into effect in May 2018, bringing with it many reasons to bolster your data security, including enhancing your vulnerability management program, in a bid to protect with “appropriate technical and organisational measures.” [iii]
A common theme both UK and Stateside seems to be unpatched vulnerabilities, often spanning several years. In its 2016 Data Breach Investigations Report (DBIR), Verizon said hackers view these long-disclosed CVEs (Common Vulnerabilities and Exposures) as “oldies that are still goodies”, which remain unpatched in many organisations. The report stated: “Hackers use what works, and what works doesn’t seem to change all that often.”
Two of the largest breaches to hit mainstream news recently both occurred due to vulnerabilities where patches had already been released[iv].
- Equifax – if you have kept up with this breach, you’ll know that Equifax has now confirmed that attackers entered their network through a web-application vulnerability in May for which a patch had been made available in March. In the words of Vice president Rene Gielen of Apache, whose product was the one affected: “Most breaches we become aware of are caused by failure to update software components that are known to be vulnerable for months or even years.”
- WannaCry – one of the more prolific recent attacks exploiting a known Microsoft vulnerability for which a patch was released in March. In May, the Shadowbrokers released an NSA tool to exploit this vulnerability and thousands of endpoints – from single users to the NHS – were and continue to be affected. The NHS was especially vulnerable due to running an XP estate whose support had ceased in 2014.
Where do you begin?[v]
It is fair to say that patching is neither easy nor cheap and it will compete with a million other priorities. But there are plenty of resources online to help formulate a plan and, below, we have listed some tips and links taken from various blogs, guides and vendors sites in a bid to help you get your plan started.
1. Which elements of your IT infrastructure require patches?
The first step is to investigate, noting all the computer devices and assets that reside on your network. It may be worth detailing how many IoT (Internet of Things) devices you have as these present a separate set of concerns, not least since many currently contain no way to update software. But with the increase in breaches on IoT, this is a great time to specify the hardware you have together with what can and cannot be patched.
Beware legacy and end-of-life systems. A recent GCHQ whitepaper describes a server survey, where shockingly over 600,000 active servers worldwide still run on Microsoft Server 2003, including many banks and corporations. Despite being a 12-year-old operating system, which is no longer supported or receiving updates from Microsoft, Server 2003 is also still running an estimated 175 million websites.
The danger arises from hackers who ‘reverse engineer’ patches written for newer versions of Microsoft Server and use the vulnerabilities to attack older editions.
With the passing of time, the situation just gets worse. For example, Microsoft stopped supporting Windows Server 2003 in July 2015, and in 2015 alone there were 36 vulnerabilities associated with this software.
In addition, Microsoft XP, which continues to be used by the NHS and many financial institutions, ceased to be supported in 2014 with Microsoft releasing a patch for XP users after the first waves of Ransomware spread; future bailouts shouldn’t be relied upon.
In a blog, security site Ivanti stated: “It’s not easy. It requires keeping track of all the patches issued by all the software vendors that provide products important to your enterprise. It means discovering and keeping track of which of your clients and server systems, applications, and operating systems need which patches. It means understanding the specific patch management needs of all of your most critical clients, servers, applications, and operating systems. It means using that knowledge to prioritize and execute patch acquisition, testing, and deployment. And it means doing all of this frequently enough to maximize protection of your enterprise, even as new vulnerabilities and patches continue to appear almost constantly”[vi]
2. Which patches to do you need to install and which can you ignore?
This is certainly not an easy decision but once you have a list of all of your assets you then need to rank these in order of importance and risk. Depending on the criticality of the data on the system that is affected, you can begin to assign priorities. There are various tools (see below) that can help you to scan your environment for any patches that need to be installed – not all of these will be a required, depending on your environment.
3. In which order do patches need to be installed?
By now, you should be at a stage where you know what you have got and what needs to be patched. Next, you need to decide on the order in which these patches will be applied and establish a patch cycle for regular updates. Having a plan for critical patches and updates (industry alerts and guidance) is recommended, moving forward. Whilst you won’t want to (nor be able to) patch everything all the time, you should ensure your most critical and vulnerable resources are kept up-to-date.
“Organisations should balance their security needs with their needs for usability and availability” NIST
4. What is the best, and hopefully easiest, way to install them?
With IT teams typically becoming smaller and some budgets being cut, whilst teams have multiple responsibilities it can be difficult to dedicate time to patch management. As such, there are companies and solutions that will perform automated patch management for you and for many firms, this is an ideal arrangement. Speak to us and we can advise you on a solution that will best fit your environment. Gartner and Forrester are excellent places to check on best-of-breed solutions for independent reporting.
Larger companies may use a virtualised IT infrastructure (which replicates your environment) in order to test patches before releasing them. Test computers may also be available, if not, consider testing each patch on your own PC.
Writing for TechTarget, Michael Cobb commented: “Every problem you see on your own system is one less problem that you will hear about from each of your users. Be sure to have a rollback and restore plan in place though! It is also important to frequent the relevant Internet discussion news groups to find out others’ experiences with a particular patch”.[vii]
5. Patch Testing and Implementation
The final challenge in patch management is testing, something which can be difficult for some organisations due to limited hardware and resources.
“Insufficient software inventory management processes also introduce a challenge because patch management is dependent on having a current and complete inventory of the software that is installed on every device in the environment.[vii]” say Cisco and so step 1 may alleviate some of these difficulties.
Additional layers in your security can help bolster defences, including Application Whitelisting, Application Control, Advanced Threat Protection (more information to follow when we explore how to secure your network). These will stand you in good stead particularly in zero-day threats.
Ultimately, you want to reduce the window of opportunity that an attacker may have on your organisation and, whilst you also need to have a good plan in place for catching anything untoward and then remediating it, understanding the threats and vulnerabilities in your network as well as prioritising on the right ones – is a great place to start.
Thanks for reading! I’d love to know how well your patch management process is working. What method/s do you use?
Did you find the information helpful and do you have any tips and tricks to share? If so, please email: anna.gonzalez@utilize.co.uk
Independent Research:
Gartner
Forrester
FOC Tools:
Microsoft Security Tools
Microsoft Baseline Security Analyzer
Microsoft Security Assessment Tool
Patch Management solutions:
Symantec
Solarwinds
Sysaid
Cisco
Kaseya
Ivanti
Guides:
Microsoft – Patching best practice
GDPR – Compliance
GCHQ – Guide to Patching
NIST – Guide to Enterprise Patching
Links:
Blog review of five of the best Patch Management tools
Cisco Blog: Patch Management overview
SecureWorks blog
Cipher – Best Practices
Sophos – Application Whitelisting for servers
Sophos – Sandstorm: Sandbox
[i] https://nakedsecurity.sophos.com/2017/10/30/hacking-site-hacked-by-hackers/
[ii] https://www.cyberaware.gov.uk/?gclid=EAIaIQobChMIntHGo4ib1wIV0mYbCh1EAgPBEAAYASAAEgKbLfD_BwE
[iii] https://blog.qualys.com/news/2017/08/02/countdown-to-gdpr-manage-vulnerabilities
[iv] https://www.wired.com/story/equifax-breach-no-excuse/
[v] https://blog.sysaid.com/entry/5-steps-better-patch-management-securer-business
[vi] https://www.ivanti.com/blog/equifax-breach-patch-management-cybersecurity/
[vii] http://searchsecurity.techtarget.com/answer/What-is-an-ideal-patch-management-process-for-small-businesses
[vii] https://blogs.cisco.com/security/patch-management-overview-challenges-and-recommendations











