The quilted data center: managing patches galore

Opinion
Sep 28, 20043 mins

* Patch management best practices

Software systems are inherently in constant decay. Security specialists discover vulnerabilities almost on a daily basis, while vendors keep adding features – exasperating the problem by potentially creating bugs.

In a data center environment containing a variety of operating systems, applications, network appliances and security systems, maintaining software integrity and security is a struggle, and patch management has become a substantial headache for data center managers everywhere. Nemertes Research’s interviews with IT executives show patch management and vulnerability scanning as one of the top security initiatives for this and next year.

For most enterprise data centers, every new patch presents a dilemma: installing a patch presents the risk of software conflicts and failures due to unanticipated changes in functionality. Not installing the patch exposes the infrastructure to known vulnerabilities that will be attacked. Deciding whether to apply a patch is a complex exercise of balancing risk, exposure and countermeasures. The near-infinite number of possible configurations makes applying even the simplest patch on production systems a gamble.

IT executives need to develop business processes for managing patches across the infrastructure. Special software tools can be used to automate some of this patch management process. Here are some of the best practices that have emerged in the field of patch management. IT executives can:

* Assemble cross-functional teams that can evaluate the impact of a new patch across the infrastructure. Such teams should include representatives from the applications groups, the system administrators, the network operators and security.

* Develop a formal process for evaluating the risk profile of each major patch. The evaluation of risk should involve a calculation of the severity of the vulnerability, the potential countermeasures that could be deployed instead of a patch and the relative risk to production systems if the patch is deployed.

* Perform continuous audits of the infrastructure to create an up-to-date inventory of all installed software and the revision (version) number of each component.

* Segregate development systems from production systems to allow different software revisions to be independently tested as part of a quality assurance process. Patches that are not critical should be deployed as part of regular maintenance.

* Use patch management software to automatically detect unpatched systems and “push” patches out to the infrastructure. Sophisticated products are available. Microsoft’s SMS, Configuresoft’s SUM, Altiris Patch Management, Patchlink’s Update, GFi’s Languard, BigFix’s Patch Manager and Citadel’s Hercules are just a few of the available systems.

The complexity of patch management is often exasperated by highly heterogeneous infrastructures. One of the advantages of a “flexible” next-generation data center is that it is homogeneous, made of interchangeable components with standardized configurations. In a heterogeneous data center running single-purpose servers with customized configurations, automatic patch management is almost impossible. Each server will behave differently and may be adversely affected by a patch which applied without problems on all the other servers.