By Staff Writer E-Commerce Times
02/13/04 2:15 PM PT
Noting that personal firewalls did a good job of thwarting worms like MS Blast, Gartner vice president Richard Stiennon told the E-Commerce Times that Gartner is recommending firewalls for all computers, including desktops.
Run Your Entire Contact Center in the Cloud Many businesses are increasingly seeking ways to improve the quality, flexibility, and scalability of their traditional call centers. Download this free white paper and learn the top 8 reasons to consider going virtual.
In response to Microsoft's (Nasdaq: MSFT) latest vulnerability announcement, a group of security analysts at Gartner has released a research note that advises enterprises against using Windows Server 2003 in mission-critical applications exposed to the Internet before the second quarter of 2004.
"We may have to revise this cautious position if Microsoft fails to commit publicly to extraordinary efforts to eliminate glaring holes in its operating system," the research note said.
The note also recommends that enterprises install the latest Microsoft patch on all PCs and servers, block vulnerable ports as they are identified, correctly configure enterprise firewalls, and install personal firewalls on all PCs and intrusion prevention software on all business-critical Windows servers. The goal: "to avoid the mass attacks that will almost inevitably attempt to exploit this vulnerability within the next few weeks."
Frustrated Enterprises
Richard Stiennon, vice president of research for Internet security at Gartner (NYSE: IT) and one of the authors of the research note, said that when he and fellow Gartner analysts tell clients to patch and block, as they have for past Microsoft vulnerabilities, those clients are becoming increasingly upset about receiving such recommendations.
"It is advice that is so obvious yet so difficult to do. And it often has to be done at horrendous cost," Stiennon told the E-Commerce Times.
"One major financial institution had to go to its board of directors to approve an additional $10 million to finish this patch," he added. "After MS Blast and the cost of patching that, it's, 'Here we go again,' as new vulnerabilities are found deeply ingrained in Microsoft systems."
Stiennon also mentioned the plight of another financial institution that was forced to take down its IT system for three weeks to patch its Windows desktop machines.
Not Just for Servers Anymore
Stiennon said that in the past, enterprises deployed firewalls mostly for servers and mobile computers, believing that desktop PCs were protected by the servers to which they were connected. Now, enterprises are deploying firewalls for desktop machines as well.
Noting that personal firewalls did a good job of thwarting worms like MS Blast, Stiennon said Gartner is recommending firewalls for all computers, including desktops.
"It is another expense, though enterprises understand that the cost is lower than repairing computers after an attack," he said.
Thinking Twice
Additionally, Gartner's research note stated, "Enterprises should continue to heavily weigh the cost of continually patching Microsoft products when deciding which operating system to purchase."
Indeed, Stiennon said the latest vulnerability, along with news that a portion of Microsoft's source code was leaked onto the Internet, has sparked debate about whether enterprises should have a diverse computing environment or rely on a monolithic solution.
"My prediction is that enterprises will think twice before installing Windows ATMs, Windows telephone systems, Windows security [systems]," he said. "Given these vulnerabilities, businesses [adding Windows machines will] have to deal with one more machine to track down and patch every month."
The Facts of Life
However, Jim Hurley, vice president for security and privacy at Aberdeen Group, told the E-Commerce Times that the difficulty of updating Windows systems to guard against vulnerabilities depends on the degree to which an organization has automated its update process.
Hurley said the predilection for enterprises using Windows is to have a central staging system that pushes out SMS technology to its client computers. According to him, the most common method of achieving this is twofold. For employees who turn on their PCs each morning, a macro is built into the boot sequence that patches Windows automatically. Those who leave their computers running are notified that a patch is available. Once activated, the patching process then takes about two or three seconds to complete.
Hurley intimated that concerns about Windows might be overstated. "Patches and vulnerabilities are a fact of life," he said.
Seeking a Model
Indeed, Guardent CTO Jerry Brady pointed out that the computer industry, for all intents and purposes, is still maturing and has taken a while to grasp risk models.
"No one has figured out yet what the dominant model will be for managing software vulnerabilities," Brady told the E-Commerce Times. "Something has got to break soon, because [the present commercial software models] do not fit the risk preferences that companies prefer."
Until recently, he said, the commercial vendor model had an advantage because its source code was not accessible to hackers. Usually, vendors like Microsoft had a grace period of knowing a vulnerability existed before it could be exploited.
Now, as software becomes larger and more complex, vendors like Microsoft will have to find a different method of conducting defect management, most likely some combination of longer release cycles and more expensive software.
"No one has figured out a [product] life cycle that has made sense," Brady said.
Worst Elements
Meanwhile, the recent news about Windows source-code leaks demonstrates the worst elements of closed-source software, Brady said. Because using Microsoft's proprietary code would violate the law under the Digital Millennium Copyright Act (DMCA), "the bad guys get to find out about it before the good guys."
In contrast to Windows, Stiennon said, Linux enables computers to communicate using standard protocols that are tested in an open forum.
"The irony here is that, if Microsoft announces more vulnerabilities more quickly, they are leaking out the notion that open source is actually a better process" in defending against vulnerabilities, Stiennon said.
Gartner is fickle. They will ride the waves. If MS is popular they will tout them as the ...
Next Article in Security
Friday the 13th Unlucky for Microsoft, Windows Users February 13, 2004
"This is definitely impacting the bottom line for Microsoft," iDefense director of malicious code Ken Dunham told TechNewsWorld. "They are losing steam in the sales area and losing ground in servers because of security issues. It may not be the courts that dissolve the monopoly of Microsoft, but it may be the attackers."
Related Stories
Deepening the Firewall: Exclusive Interview with NetScreen Executive Officer David Flynn January 08, 2004
"Historically, the two primary competitors we see are Cisco and Check Point Software, but as this new smarter firewall comes along, we're seeing some of the antivirus companies, like Symantec and Network Associates, trying to move in this direction," NetScreen's David Flynn told the E-Commerce Times.
If Microsoft Changed, Would Anyone Notice? December 15, 2003
I'm not expecting Linux or Apple advocates to scream suddenly about how much they now love Microsoft. I don't have access to those kinds of mind-altering drugs. I'm only suggesting that Microsoft seems to be busting its hump to change, and wondering how many users out there will allow themselves to notice.
The State of Software Security: An Interview with ISS Founder and CTO Chris Klaus December 03, 2003
"Linux exploits tend not to receive as much attention or awareness compared to a Microsoft threat," Chris Klaus, CTO of Internet Security Systems, told TechNewsWorld. "As we see more governments and companies standardizing on Linux within their own desktop and server infrastructure, Linux will become a bigger target in the future."
How Much Is a Hacker's Head Worth? November 19, 2003
On the positive side, if virus writers continue to brag about their exploits, as they are notorious for doing, Microsoft's reward could encourage "witnesses" to come forward. On the other hand, the bounty could drive malware creators further underground.
Microsoft Patches Up Push for Better Security October 10, 2003
The final piece of the new initiative will involve planned updates in the first half of 2004 for both Windows XP and Windows Server 2003, which was released just a few months ago.
Related News Alerts
More by Staff Writer
A Midsummer's Mac Death Match, Round Two: Enderle vs. Chaffin July 13, 2004
MacNewsWorld presents round two of our three-round Midsummer Mac Death Match, in which Mac Observer editor-in-chief Bryan Chaffin and the always-controversial industry analyst Rob Enderle square off on one of today's key Mac issues. Today Enderle and Chaffin eachs kicks metaphorical mounds of sand on the arguments the other made in round one on the question of where Apple will be five years from now.
A Midsummer's Mac Death Match, Round One: Enderle vs. Chaffin July 12, 2004
MacNewsWorld presents round one of our three-round Midsummer Mac Death Match. Today, Mac Observer editor-in-chief Bryan Chaffin and the always-controversial industry analyst Rob Enderle each offer their predictions of what sort of company Apple will be in five years. Will Apple rule the "Digital Life" -- or be the Atari of 2009?
PeopleSoft Blames Oracle for Share Price Free Fall July 07, 2004
Forrester vice president and CRM analyst Erin Kinikin described PeopleSoft as being on a very narrow tightrope since Oracle first made its takeover offer. "To prove [it] can survive as an independent company, PeopleSoft has to make its numbers," Kinikin told CRM Buyer. "Any time PeopleSoft pre-announces lower earnings, people are going to wonder if [it is] falling off the tightrope."