stopping the adobe, apple and java software updater insanity

22
Stopping the Adobe, Apple and Java Software Updater Insanity © 2012 Monterey Technology Group Inc.

Upload: lumension

Post on 08-Jun-2015

717 views

Category:

Technology


0 download

DESCRIPTION

This presentation by Randy Franklin Smith from Ultimate Windows Security reviews, “Stopping the Adobe, Apple and Java Software Updater Insanity”. He shares tips and caveats for dealing with the most common software updaters from Adobe, Apple and Oracle. But the bottom line is that we all need centralized patch management and he’ll explore the important requirements and architectural issues you should be aware of in this space.

TRANSCRIPT

Page 1: Stopping the Adobe, Apple and Java Software Updater Insanity

Stopping the Adobe, Apple and Java Software

Updater Insanity

© 2012 Monterey Technology Group Inc.

Page 2: Stopping the Adobe, Apple and Java Software Updater Insanity

Brought to you by

Speaker Russ Ernst – Group Product Manager

www.lumension.com

Page 3: Stopping the Adobe, Apple and Java Software Updater Insanity

Preview of Key Points

© 2012 Monterey Technology Group Inc.

TrendsStatisticsUpdater problemsCentralized, multi-vendor patch management

Page 4: Stopping the Adobe, Apple and Java Software Updater Insanity

Poll

© 2012 Monterey Technology Group Inc.

Which 3rd party vendor tool causes the most trouble in your environment?

Page 5: Stopping the Adobe, Apple and Java Software Updater Insanity

Trends

© 2012 Monterey Technology Group Inc.

The risk is in the endpointThe endpoint is the most vulnerableAll endpoints are important – not just high value employees

Page 6: Stopping the Adobe, Apple and Java Software Updater Insanity

Trends

© 2012 Monterey Technology Group Inc.

The risk is in the endpointAttackers are focusing on the endpoint

• Duqu• Flame• Stuxnet• RSA• Spearfishing

Page 7: Stopping the Adobe, Apple and Java Software Updater Insanity

Trends

© 2012 Monterey Technology Group Inc.

The risk is in the endpointAttackers have the strongest motivators of all

• Politics Asian state sponsored IP Economic data Defense

• Religion• Money

Primarily Eastern Europe Looking for very specific data that can be monetized Once acquired, they’re done

Page 8: Stopping the Adobe, Apple and Java Software Updater Insanity

Statistics

© 2012 Monterey Technology Group Inc.

MS Patches compared to Non-MS

Microsoft; 32

Other; 87

Acrobat; 9

Flash; 11Shockwave; 4Java; 5

Ap-ple; 8

Firefox; 50

Page 9: Stopping the Adobe, Apple and Java Software Updater Insanity

Trends

© 2012 Monterey Technology Group Inc.

The risk is in the endpointTargeted attacks makes it harder for AV vendors to protect you

Patch speed is increasingly important• Zero day exploits

But that’s hard when you have patches from many vendors and no centralized way to control them

Page 10: Stopping the Adobe, Apple and Java Software Updater Insanity

Non-MS Patching

© 2012 Monterey Technology Group Inc.

Each product (not even each vendor) has its own updater

No centralized controlAre updaters installed?Do employees remove or disable them?Do employees allow them to complete?Are patches failing?How up-to-date are patches across the fleet?

Page 11: Stopping the Adobe, Apple and Java Software Updater Insanity

Non-MS Patching

© 2012 Monterey Technology Group Inc.

Performance issuesEvery PC downloading updates at the same time

Other issuesOther unwanted software installed

• Ask and Google toolbars

Silent updatesJava

Need I say more?

Page 12: Stopping the Adobe, Apple and Java Software Updater Insanity

Non-MS Patching

© 2012 Monterey Technology Group Inc.

How many updaters?Updater for Adobe AirUpdater for Adobe Flash PlayerUpdater for Adobe Reader/AcrobatUpdater for Adobe Shockwave PlayerUpdater for Apple iTunesUpdater for Apple QuickTimeUpdater for Oracle JavaUpdater for Mozilla FirefoxHardware updaters

• Laptop• Mouse• Video

Page 13: Stopping the Adobe, Apple and Java Software Updater Insanity

Another development

© 2012 Monterey Technology Group Inc.

Microsoft’s auto-update infrastructure has been compromised already?

How hard would it be to compromise someone elses?

Page 14: Stopping the Adobe, Apple and Java Software Updater Insanity

Other facts

© 2012 Monterey Technology Group Inc.

Patches often need to be chainedNot cumulative

Page 15: Stopping the Adobe, Apple and Java Software Updater Insanity

Bottom Line

© 2012 Monterey Technology Group Inc.

Need in-house controlled patchingCentralizedMulti-vendorMulti-platform

Page 16: Stopping the Adobe, Apple and Java Software Updater Insanity

Tips for the meantime

© 2012 Monterey Technology Group Inc.

Patches may need to be chainedSubscribe to multi-vendor patch update

serviceshttp://leic.lumension.com/

Make sure you know what’s on your networkFree: Lumension Application Scanner Tool

Page 17: Stopping the Adobe, Apple and Java Software Updater Insanity

Tips for the meantime

© 2012 Monterey Technology Group Inc.

Familiarize yourself with each vendor/product Update site/blog How they notify; subscribe How their patches usually work Develop a plan for each product that needs regular patching

• Evaluate risk and exposure• Determine testing if any

Some patches can be pushed out If not then you have to hope for the best

• That updater on each PC is doing its job

Follow up with vulnerability scans• Do vulnerability scanners find this?• Free: Lumension Vulnerability Scanner

Page 18: Stopping the Adobe, Apple and Java Software Updater Insanity

Bottom Line

© 2012 Monterey Technology Group Inc.

Need in-house controlled patchingCentralizedMulti-vendorMulti-platform

Page 19: Stopping the Adobe, Apple and Java Software Updater Insanity

Brought to you by

Speaker Russ Ernst – Group Product Manager

www.lumension.com

Page 20: Stopping the Adobe, Apple and Java Software Updater Insanity

•Lumension Endpoint Management and Security Suite is an extensible solution suite that reduces complexity, optimizes TCO, improves visibility and delivers control back to IT.

Streamline Patch Management Across Your Environment

» Reduces Complexity and TCO through effective automation of operational tasks

» Provides Greater Visibility and Into Control Over your network’s endpoints

» Improves Operational Efficiency with a single console to manage multiple functions

» Elevates Security and Compliance Posture through automatic policy enforcement

20

Page 21: Stopping the Adobe, Apple and Java Software Updater Insanity

Patch is Core Component of Defense-in-Depth

BlacklistingAs The Core

Zero Day

3rd Party Application

Risk

MalwareAs a

Service

Consumerizationof IT

Defense-N-Depth

Traditional Endpoint Security

Patch & Configuration

Mgmt.

Emerging Endpoint Security Stack

21

Page 22: Stopping the Adobe, Apple and Java Software Updater Insanity

SecuritySCAPE 2012: Virtual Event 9/25-9/26/12

22

Register for this FREE virtual event!

»http://www.securityscape2012.com