by Chris Andrew, special to Network World

Patch management goes automatic

How-To
Oct 18, 20043 mins

Staying current with vendor security alerts, assessing the risk that these vulnerabilities pose to your business and testing and applying software patches to close these holes are onerous tasks that can consume most of an IT professional’s workday.

An automated patch-management system provides more effective security by tracking machines that need patches and applying required patches and updates throughout a corporation.

Automated patch-management software offers a solution for aggregating, and distributing and installing patches and software updates for multiple computing platforms. The core functions of the system are an accurate patch management detection and inventory process, and automatic patch deployment across platforms.

In distributed corporate environments, a detailed inventory of system components is essential, especially the software that runs those systems. Third-party patch management systems conduct this inventory one of two ways: either with or without agent software.

Agents allow for deeper host inspection, enforcement and the ability to perform arbitrary tasks on targets. Advanced client-side agents allow for communication with a host server. A primary reason and underlying benefit of agent technology is increased performance and scalability. They accelerate the performance of a large-scale deployment, and one enhanced server can service tens of thousands of Web-based client agents. By using agents, a patch management system can work across firewalls and operate on any computer that has a TCP/IP connection to an enterprise network.

At the other end of the spectrum is the agentless option – technology that requires manually downloading patches to a host server and then pushing them out to target servers and/or desktops via remote process control. In the past, those wanting a lighter software thumbprint and rapid patch management deployment preferred this methodology. However, significant strides in reducing the agent size and improvements in agent-based management and agility have addressed this concern.

Effective patch management solutions let a central administrator or group of administrators automate the discovery of software vulnerabilities and subsequent distribution of security patches throughout a heterogeneous enterprise network. Both agent and agentless systems search for and identify vulnerabilities. The inspection process can range from registry evaluations to more accurate inventories of Dynamic Link Libraries and other system files.

Once a vulnerability has been identified, a patch management system lets administrators select the corresponding patch from a list of known patches (or pull it directly from the vendor if the product doesn’t perform local patch caching) and propagate that patch to vulnerable machines.

More-sophisticated patch management systems are equipped with features that make the patch-deployment process more intuitive, secure and efficient. For example, certain systems let administrators create groups of computers within a network to expedite the patching process. Other important features in enterprise patch management systems are the ability to remediate against mandatory baselines; the creation of role-based administration control to enable specific functional access by various users; and the ability to aggregate enterprise-reporting data from multiple patch management servers.

Additional features, including patch rollback, ongoing audit and compliance controls, inventory reporting, and the ability to create custom patches for home-grown applications, let some automated patch-management systems deliver a comprehensive solution to meet the vulnerability detection and remediation needs of firms.

Automated patch-management systems help support a company’s patch management best practices.

Andrew is vice president of product management for PatchLink. He can be reached at chrisa@patchlink.com.