by Mandy Andress

Patch management start-ups face pressure from all sides

How-To
Jan 17, 20055 mins

It’s all about control of the software agent sitting on the desktop.

Pure-play vendors such as Shavlik Technologies, BigFix and PatchLink got off to an early lead in the patch management game, but many established security  vendors are adding patching to their arsenals. This means more choices for users, and it means the pure-play leaders need to adapt quickly to the trend toward multipurpose tools.

While software should be developed with a focus on minimizing security issues in the first place, the reality is that you’ll always need to understand what is running in your environment and have the ability to deploy updates quickly and easily.

And the need for patch management grows stronger every day. Virus/worm/Trojan/phishing  technology is only getting more sophisticated, probing for vulnerabilities in e-mail, Web browsers, instant messaging, file sharing and the like.

A company only needs to be brought to its knees once with an infection to understand the importance of patching. Personal firewallsintrusion prevention , and other mitigating controls can be implemented, but patching is the only way to get to the root of the problem.

The patching landscape

•  First of all, operating system vendors are providing products focused on their individual platforms. Microsoft released Software Update Service (SUS) and has the next-generation Windows Update Services (WUS), in beta (see test). Red Hat has added a patch management offering for its enterprise products, although it is a bit pricey.

Microsoft is quickly gaining ground in this area, especially because its tools are free. As functionality continues to evolve in WUS, some companies are having a hard time justifying the cost of the current pure-play patch management products when they can get similar functionality at no charge.

But most companies are not a one-shop environment, so they are implementing one patch management process for Windows, one for Linux and a third for Solaris. This is not ideal, so many are looking for a patch management solution that provides cross-platform support.

•  Asset/configuration management companies are really taking charge of the patch management arena. They are in the ideal position because they already have agents running on all managed systems and have access to see what is installed and configured. Add some functionality for identifying missing patches, plug that in to the software deployment mechanism, and a new patch management module is born.

Altiris, Configuresoft and LANDesk are a few of the heavy hitters in this area.

•  Vulnerability assessment products also are joining the fray. They can identify missing patches on a system; they just need to add a deployment mechanism. Citadel (see recent test results) already fills this gap, taking assessment results and providing remediation actions. Visionael also has a remediation module for its vulnerability assessment product. At this point, I don’t see vulnerability assessment products becoming the primary patch management product in a company, but they will be used mainly as a central point of remediation.

Network access/endpoint security and compliance products are beginning to mature, though, and they offer similar functionality, focusing on deploying patches to systems that don’t adhere to the defined corporate standard. InfoExpress CyberGateKeeper will deploy patches to a system before allowing network access. SecurityProfiling SysUpdate watches systems and provides remediation options, including patch deployment, for out-of-compliance systems.

Then there are the major management suite vendors – Computer Associates, for example, offers patching as part of its eTrust Vulnerability Management solution.

Faced with all this competition, pure-play vendors need to focus on integration, adding functionality for vulnerability assessment and asset management.

Customers are becoming increasingly frustrated with having three products to perform these activities when it makes more sense to have one agent on the system. From a support perspective, determining which agent is causing problems is a nightmare, as vendors usually point to the other direction when trying to troubleshoot an issue.

Convergence will occur. Security is an integral component to the basic operation of an organization, and companies can no longer ignore the inevitable. They must have an infrastructure in place to define a base standard, identify gaps in this standard on systems in the field and deploy software.

The pure-play vendors took advantage of the gap not being filled by existing management software and created patch management-focused products, but the asset management companies are catching up quickly.

Agents win the battle
In the early days, the big debate focused on agent vs. agent-free products. Most of this discussion has died down as the benefits of agent-based products in our laptop-driven world became apparent. How can you effectively push patches to systems when you never know when they will be online? Even the strongest advocates of agent-free patch management have developed agent-based alternatives.

In the end, the focus will be on controlling the agent that runs on the computer. This could be an asset management product that provides patch management functionality or a patch management product that has branched out to asset/configuration management. Either way, the ideal is one agent on each system that serves a role in asset tracking, software updates, vulnerability assessment and policy enforcement.

I still see a role for separate compliance or vulnerability assessment and remediation products because organizations need to maintain segregation of duties and still need to address point remediation instances. Plus, based on the results of our latest vulnerability management roundup, it is best to have a few different technologies looking for vulnerabilities on systems.