FedCIRC plans patch-release system

CERT Coordination Center

As federal agencies worked to stay ahead of the Code Red computer worm crawling through the Internet last week, officials were planning an automated method of fixing vulnerabilities in government systems.

Under the plan, agencies would provide profiles of the applications and operating systems on their networks to the Federal Computer Incident Response Center, which would then send agencies only the patches they needed. FedCIRC, the lead organization for civilian agency computer-attack warnings and response, is set to release a request for proposals for the system.

"It really is needed, and [Code Red] is a good example of needing to make it easy for people," said Sallie McDonald, assistant commissioner of information assurance and critical infrastructure protection at the General Services Administration. Her office houses FedCIRC.

Code Red exploits a vulnerability in Web servers using Microsoft Corp.'s Windows NT 4.0 or 2000 and Internet Information Server software. Microsoft announced the problem and released a patch to fix it July 18, but the next day, Code Red infected more than 250,000 systems, according to the CERT Coordination Center at Carnegie Mellon University.

Federal agencies worked "diligently...to install the patch in anticipation of Code Red," McDonald said.

Propagation of Code Red slowed after the initial wave, and as of Aug. 2, "from the thousands of federal systems, we have only had one incident reported from one agency," McDonald said.

System vulnerabilities are common, and patches for them are released so often that system administrators have a hard time keeping up, said agency chief information officers, including John Gilligan, the CIO Council's security committee co-chairman.

Featured

  • Telecommunications
    Stock photo ID: 658810513 By asharkyu

    GSA extends EIS deadline to 2023

    Agencies are getting up to three more years on existing telecom contracts before having to shift to the $50 billion Enterprise Infrastructure Solutions vehicle.

  • Workforce
    Shutterstock image ID: 569172169 By Zenzen

    OMB looks to retrain feds to fill cyber needs

    The federal government is taking steps to fill high-demand, skills-gap positions in tech by retraining employees already working within agencies without a cyber or IT background.

  • Acquisition
    GSA Headquarters (Photo by Rena Schild/Shutterstock)

    GSA to consolidate multiple award schedules

    The General Services Administration plans to consolidate dozens of its buying schedules across product areas including IT and services to reduce duplication.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.