FedCIRC plans patch-release system

CERT Coordination Center

As federal agencies worked to stay ahead of the Code Red computer worm crawling through the Internet last week, officials were planning an automated method of fixing vulnerabilities in government systems.

Under the plan, agencies would provide profiles of the applications and operating systems on their networks to the Federal Computer Incident Response Center, which would then send agencies only the patches they needed. FedCIRC, the lead organization for civilian agency computer-attack warnings and response, is set to release a request for proposals for the system.

"It really is needed, and [Code Red] is a good example of needing to make it easy for people," said Sallie McDonald, assistant commissioner of information assurance and critical infrastructure protection at the General Services Administration. Her office houses FedCIRC.

Code Red exploits a vulnerability in Web servers using Microsoft Corp.'s Windows NT 4.0 or 2000 and Internet Information Server software. Microsoft announced the problem and released a patch to fix it July 18, but the next day, Code Red infected more than 250,000 systems, according to the CERT Coordination Center at Carnegie Mellon University.

Federal agencies worked "diligently...to install the patch in anticipation of Code Red," McDonald said.

Propagation of Code Red slowed after the initial wave, and as of Aug. 2, "from the thousands of federal systems, we have only had one incident reported from one agency," McDonald said.

System vulnerabilities are common, and patches for them are released so often that system administrators have a hard time keeping up, said agency chief information officers, including John Gilligan, the CIO Council's security committee co-chairman.

Featured

  • Budget
    Stock photo ID: 134176955 By Richard Cavalleri

    House passes stopgap spending bill

    The current appropriations bills are set to expire on Oct. 1; the bill now goes to the Senate where it is expected to pass.

  • Defense
    concept image of radio communication (DARPA)

    What to look for in DOD's coming spectrum strategy

    Interoperability, integration and JADC2 are likely to figure into an updated electromagnetic spectrum strategy expected soon from the Department of Defense.

Stay Connected