by Mandy Andress, Network World Alliance

Patch-management products move toward remediation

Reviews
Dec 11, 200617 mins

Test shows BigFix, McAfee and PatchLink lead in easing remediation woes

Patch-management products have evolved from simply pushing out patches to now encompassing more preemptive security measures, including manipulating security configuration settings, deploying standard software packages, maintaining policy compliance and taking an active role in vulnerability remediation.


BigFix Enterprise Suite came out on top as the Clear Choice winner, performing well in all categories and standing out in ease of use and customization capabilities. McAfee’s Hercules was a close second, falling slightly behind in its customization capabilities. PatchLink Update rounds out the top three. While it lacks some native support for advanced customization and reporting capabilities we were looking for in a product of this class, PatchLink does make these functions available in add-on components.

ProductBigFix Enterprise Suite 6.0McAfee (formerly Citadel) Hercules Remediation ManagerPatchLink Update 6.3
VendorBigFixMcAfeePatchLink
Price as tested$40 per seat, per year.$75,800 as tested, includes licensing and support for 500 workstations and 100 servers.$1,495 per server and $18 per node.
Pros

Best reporting; Custom Fixlets enable custom remediation actions; very easy to use.

Best interface; detailed access control.Strong complement of default reports that can be easily filtered based on key criteria; detailed access control.
Cons

Detailed access control could be improved.

Custom report engine not fully integrated into the product and is difficult to use.Separate components to get full custom packages and reporting.
Score4.44.354.25
ProductLANDesk Security Suite 8.7Altiris Client Security Management Suite 6.2Kace 3.0 (KBOX 1000 Series)
VendorLANDesk SoftwareAltirisKace Networks
Price as testedStarts at $59 per node.Starts at $88 per node plus $69 per node for patch management.Starts at $9,500.
ProsBased on strong foundation Management Suite, which allows for adding additional LANDesk services on a single platform.Client Security Management Suite adds endpoint security and application security in a single client.Appliance model allows for quick setup; ticketing supported; alerting service is unique.
ConsDifficult to navigate with poor user interface; custom scripting language required for custom remediation.Security Expressions not fully integrated into suite; patch deployment configuration lacks advanced options.Security components seem to take a back seat to ticket system and software distribution.
Score3.883.73.4
The breakdown BigFixCitadelPatchLinkLANDeskAltirisKace
Remediation functionality 30%54.54.54.554.5
Product management and administration 25%54.553.52.54
Remediation workflow 15%33.53.532.53.5
Access control 15%354.544.51.5
Reporting 15%54343.52
TOTAL SCORE4.44.354.253.883.73.4
Scoring Key: 5: Exceptional; 4: Very good; 3: Average; 2: Below average; 1: Subpar or not available

We tested five key areas of each product:

* Remediation functionality tests exercised how well a product could remedy a system issue through support for the operating system overall, via patches, registry key and other configuration changes. Additionally we assessed how it facilitated manual and scheduled remediation tasks and whether it offered the ability to create custom remediation tasks.

* Remediation ticketing/workflow tests examined how well a product could implement a remediation process, including end-to-end management of the cycle.

* Reporting tests evaluated how well a product could provide useful information, through default and custom reports, on remediation tasks to administrators and management personnel.

* Access-control tests examined how access to the product could be controlled, focusing on flexibility, granularity and integration with standard enterprise user repositories.

* Product management and administration tests focused on what you need to do to use the product on a daily basis and keep it running.

Here are the details of how each product fared in our testing (see “How we did it” for a detailed test methodology).

Altiris

The Altiris Client Security Management Suite 6.1 comprises SecurityExpressions — a tool that provides the ability to check security configuration and compliance settings and then remediate those issues, via Endpoint Security, Local Security and Application Control modules. Patch Management is provided as a separate component. This combination of modules runs on the foundation architecture called the Altiris Notification Server. We focused on the SecurityExpressions and Patch Management components because that combination fulfilled the test criteria.

Altiris’ combined modules handled all the basic remediation functionality we were looking for, excelling in the ability to create custom checks, such as for a specific registry key setting, and remediation actions, such as changing a registry key setting.

SecurityExpressions is not fully integrated into the Altiris system. For example, policy development in SecurityExpressions still occurs through a separate console, but policy checks can be seen in the Altiris console. Because SecurityExpressions is the heart of vulnerability remediation, we would like to see these fully integrated so that creation of policy and configuration checks follow the same interface and process as other Altiris products.

Likewise, we would like to see Patch Management included as part of the overall Client Security Management Suite, because it is an integral piece of the remediation scheme.

Management of all the modules occurs through a Web-based console, which was cumbersome to use. It was difficult to perform simple tasks, such as scheduling a patch deployment. The management console provides several dashboards showing charts and graphs, such as missing patches based on criticality. The graphs do not provide the ability to directly drill down to see the corresponding data. This would be a nice addition to make the process of identifying security details more efficient.

Patch-deployment settings, including reboot control and user notification, are handled through configuration policies. Administrators define a policy on how patches should be deployed. This is good if your settings are the same for every deployment, but requires some additional work if you need to deploy a patch comprising different settings. We had a hard time finding the settings in the console and documentation, a condition which required that we contact customer support.

We also must note that Altiris does not support more advanced patch-deployment options available in other products, such as pause or deferral.

Access control is tied to the underlying Windows groups and is administered from the product console, so it is easy to integrate with enterprise roles and identity management processes. A few default roles, such as Administrator and Guest, are included, and administrators can create their own custom roles. Permissions are assigned to each of the roles and can be very detailed.

However, the user interface for setting security permissions means there is some lack of centralized control. You grant access from the properties tab for different objects as opposed to defining access control from a centralized point. For example, if you want to provide access to reports, you go to the Reports permission tab and make the necessary changes.

The reporting engine provides basic functionality but could be improved. We were able to schedule report runs and create standard reports showing missing Windows patches and remediation actions taken. Exporting reports is not available within the management console. A separate utility called ImportExportUtil is available to export data from the notification server. Trend reports should be available in the next version, according to the vendor.

BigFix

The BigFix Enterprise Suite comprises the BigFix Server and management console, with agents running on client systems. The management console is a thick-client console that runs on most Windows platforms and is accessed by administrators with the appropriate credentials. Reports are available through a Web-based reporting system. For testing, we installed all management components on a single server, but they can be distributed and scaled easily.

BigFix easily handled basic remediation functions in this test. While the product supports hundreds of system checks out of the box, BigFix excels in its ability to support custom checks and custom deployments. Administrators can create customized Fixlets, the BigFix term for checks and remediation actions, with almost infinite possibility.

Usability also is a big win for BigFix, with easy right-click selection for deploying a fix on the fly. Actions can be scheduled and security baselines defined to ensure systems adhere to defined policies and standards. In our testing, BigFix was the easiest product to navigate and use.

BigFix provided the best options for deploying patches, covering the standard reboot notification and user suppression options. BigFix also provided some options not available in other products we reviewed, such as the ability to define a specific system criteria or attribute to provide additional detail controls for the remediation measures we were deploying. For example, we were able to define that a system must match a specific Active Directory path before the desired remediation action would take place.

There is a wizard available to create a patch-deployment rollback, which helps ease the process but is a little cumbersome.

One area where BigFix could use some improvement is access control. The product includes only three roles and offers only the ability to control a few user privileges.

The Web-based reporting system was the best we tested, providing an intuitive interface to create standard reports and flexibility to create custom reports. Reports can be exported to multiple formats and scheduled, with results e-mailed upon completion.

BigFix’s visualization tool is an added bonus that maps your network into a sphere for better viewing. This provides the ability to identify changing trends in your environment, such as visualizing which systems do not have a specific patch installed. This could help assist in pinpointing a network segment or remote office that is not updating properly.

McAfee (formerly Citadel)

Hercules, which has always been a remediation product at its core, comprises the core Hercules Server; the Channel Server, which handles communication with the core server; and the Download Server, which stays in sync with new vulnerabilities and remedies made available by the company. The product uses Microsoft’s SQL Reporting Services as its report engine. The Hercules agent resides on client systems.

The management interface was one of the easiest tested. One of the best features was the quick-start module that walked us through all the key actions needed to use the system, such as deploying agents, performing system inventory, launching security assessments and creating reports. The documentation provided by Hercules was excellent, accurate and easy to follow, serving as a great resource through our review process.

Access control is the strength of the McAfee package. Custom roles can be created, with each role having the ability to be assigned any subset of more than 70 identified tasks. This provides the flexibility to create access controls that best fit with an organization’s structure. For example, you can create a role for a subset of your Windows server-management team and provide team members only the specific tasks they need to perform.

Remediation functions worked well, supporting all of our key actions. One note is that while Hercules supports the creation of custom remedies, detection is not as easily defined as in other products tested. For example, you can create a remedy to run a script or change a registry key setting, but you cannot easily create a custom vulnerability check to define how to examine the system to see whether the remediation action needs to be performed.

Deployments of remediation actions were easy to perform, for both manual and scheduled tasks. For manual tasks, you select the option from the right-click menu; for scheduled tasks, you only have to walk through a wizard.

For patch-deployment options, Hercules supports standard settings, such as user deferral and user messages, but it does not support some of the advanced options, such as limiting number of deferrals or amount of time to delay a remediation action.

Reporting is one area where Hercules could use some improvement. The ability to schedule canned reports and create custom reports is available, but those tasks are done through SQL Reporting Services, not through the Hercules product itself. These tasks should be better integrated into the Hercules console for improved ease of use.

Kace

Kace KBOX is an appliance-based solution that combines patch deployment, software distribution, vulnerability assessment and help-desk ticketing services. This product is positioned as an all-in-one solution for the small to midsize enterprise.

Compared with other products we tested, functionality, user interface and reporting capabilities are not as advanced. Administration is handled through a browser-based interface that is not intuitive or easy to navigate without training.

Kace supports the standard remediation functionality we tested, except for wide operating-system support, as it maintains only Windows systems. Patches, configuration changes, software deployments and custom scripts are defined and deployed by the system as advertised.

User authentication can be integrated with a central repository such as , but the access control thus facilitated is minimal. The system allows for only three access roles, with no ability to add your own. You also cannot modify function assignments.

A number of default reports are included, but only a small subset relates to patch and remediation deployments. A larger number of the reports deal with the ticketing system, handing out reports on tickets per user and time to closure per ticket, for example. Custom reports are available, but the user needs to write the specific SQL query that will generate the desired report.

The help-desk ticketing system — where users can submit requests, such as my computer won’t start, I need to have Visio installed, I can’t access the Internet — is a nice feature, but we would like to see increased remediation integration and workflow capabilities. The system has a unique feature in that it can generate a number of alerts, such as alerts calling for specific administrative actions.

We would not recommend KBOX as a stand-alone enterprise remediation tool, but a company looking for a cost-effective solution to handle software deployment, license tracking, system configuration and help desk ticketing would do well to evaluate this product.

LANDesk

LANDesk Security Suite runs as a component of the foundation LANDesk Management Suite. While this product handles many of the functions we tested, its overall usability is poor, and it was challenging to navigate. We referred frequently to the product documentation, which also was hard to follow. It did not contain any tutorial screen shots, and trying to follow the documented steps often resulted in looking for menu items or screens that did not exist.

LANDesk supports all operating-system platforms and remediation functionality included in our test, but support for non-Windows platforms is limited. One example is the inability to handle bandwidth detection for Unix systems, a feature that is available with the Windows agent. While LANDesk supports custom scripts, an unnamed custom scripting language is used to create them, so administrators have an increased learning curve for this functionality.

The ability to send alerts when configuration changes are made or patches are missing from monitored systems is well integrated into the product and supports multiple communications media including and e-mail. LANDesk rollback capabilities are driven solely by the patches deployed. Even if remediation is driven by a vulnerability that contains multiple patches, you cannot roll back by vulnerability; you must roll back the individual patches comprising the vulnerability remediation action.

Access-control functionality meets our overall criteria for our tests, but usability and administration could be easier. Scopes are defined to identify what particular users can access, as well as what functions they can complete once they have accessed those machines. For example, you can specify that Windows administrators can access only Windows systems, and not the Unix systems, and only install Windows patches once they’ve hit the machines. We would like to see more options in the functions allowed to each administrator because that would help provide increased security administration detail.

LANDesk supports sending alerts on defined events, patch rollback and many deployment configuration options. For example, administrators can show scan progress, defer install, send messages to users, allow cancellation, and control bandwidth consumption on deployments.

Reporting capabilities shipped with the Security Suite are strong. Multiple formats (pdf, html, xls) are available, reports can be scheduled and we were able to create most of our test reports. We would like to see the ability to select time frames for report generation, a function available in many of the other products. Creating custom reports is supported through the custom report designer utility, a tool we found to be complex to use but very complete in its functionality.

LANDesk Security Suite has the functionality, but using the product is difficult. Several other products we tested, such as BigFix, do a better job combining strong technical functionality with ease of use and administration.

For this test, PatchLink submitted PatchLink Update 6.3, its newest release. While this product contains aspects of all the functionality we tested, PatchLink has add-on components that would further enhance its offering, such as enterprise reporting services and the developer’s kit. Overall, PatchLink Update is a very solid remediation product that should be included on anyone’s short list.

PatchLink Update is a Web-based system with almost all administration occurring through the browser-based interface, which is easy to navigate and understand. The exception lies in the software agent management center, which helps deploy and manage agent software distribution. Agents can be deployed through the Web interface, but this additional software helps with bulk distribution.

All of the remediation functionality we required for this test was available and worked well. Available are multiple operating-system support, software deployment, registry key changes and configuration changes.

Manual and scheduled remediation services are available and worked as advertised in our testing. Setup is handled through a wizard process, making it easy for first-time users and ensuring no steps are missed. For custom changes, PatchLink Update supports creating packages for deployment, similar to McAfee remedies. What you cannot do in the base product is create a vulnerability check that can tell you which systems need to have this task deployed. For example, if a system has a registry key that can tell you if the software version needs to be updated, you cannot perform that check with a custom package until you purchase the developer’s kit, according to the company.

Most remediation in PatchLink occurs through a wizard that steps the user through the processes, such as scheduling a deployment or creating a package. This prevents users from forgetting critical steps in the process, such as checking deployment settings before pushing an update.

The reporting facility in PatchLink Update is a collection of about 20 predefined reports, but this appears to be a comprehensive list that could be manipulated with quite a bit of flexibility. We were able to create all of our reports during testing, except one that shows time to remediation for an issue from initial detection. Additionally, you can go into the console and create a report based on a defined time frame, but you cannot schedule a report to run on a recurring basis with the results automatically e-mailed to you, for example.

Access control is very detailed and flexible. Only a handful of roles are defined by default, but administrators can create more roles via the Web management console. Function assignments for these roles are very detailed so that user access is limited to necessary functions.

Conclusion

Overall, these patch-management products have adequately expanded their horizons to help remediate general security concerns across deployed systems. But we would like to see them keep moving along in the right direction.

Specifically, as compliance requirements and change management processes continue to grow in importance in organizations, we would like to see these products expand their remediation workflow functionality (which was rather weak across the board in this test) to track approvals necessary to complete the remediation tasks. For example, when a new vulnerability is identified on a system requiring remediation, the process by which the remediation should occur, the manager approving the remediation measures, and the technician taking remediation actions should all be tracked by the system.

Playing to that same compliance requirement argument, the reporting capabilities of these products, while much improved over standard patch management tools of old, need to improve to provide the flexibility required for both the technical and business arms of enterprise organizations.

Andress is president of ArcSec Technologies, a security company focusing on product reviews and analysis. She can be reached at mandy@arcsec.com.

BIO HERE