Beyond patch management

A few companies are beginning to add capabilities beyond patch management to their software. "They're starting to talk more about vulnerability management, where patch management is [a] piece of what they do," said Mike Jones, vice president for marketing at Citadel. The lack of up-to-date patches accounts for only 30 percent of the security vulnerabilities to which computers are susceptible, he said.

Some vulnerability management systems have useful features, such as a mechanism for limiting the amount of bandwidth that the systems use when they distribute patches, said Ted Ritter, director for cybersecurity at Intelligent Decisions Inc., a systems integration company.

Several of the vulnerability management systems also offer quarantine capabilities, Ritter said. When a system connects to the network, it immediately is prevented from doing anything until it is checked to see that it has all of the latest patches and that it conforms to the configuration and password policies of the organization. "We think that's going to be huge," Ritter said.

Some security experts think that with better compilers and code scanning tools — and even a few hardware tricks — future software releases from Microsoft and other companies will have fewer security holes that require patching. "There are compilers, for example, that will virtually eliminate buffer overflow problems," said Peter Mell, a computer scientist in the Computer Security Division at the National Institute of Standards and Technology. Buffer overflows are one of the most frequent sources of built-in security flaws in software. During a buffer overflow attack, a program or process tries to store excessive amounts of data in a buffer or temporary data storage area.

Featured

  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.