two
Volume 6, Number 29 -- August 6, 2008

Microsoft Works to Put the Clamps on 'Exploit Wednesday'

Published: August 6, 2008

by Alex Woodie

Microsoft took two steps yesterday to help thwart the "Exploit Wednesday" events following the monthly "Patch Tuesday" releases. At the annual Black Hat USA conference this week in Las Vegas, the company announced a new program to share details of newly patched vulnerabilities with software vendors before sharing them with the public and malware writers. It also unveiled a new "vulnerability index" to provide more detail on the relative danger that each newly discovered flaw poses.

It really is a predictable result: Announce the details of security vulnerabilities at a pre-determined interval, and sooner or later, hackers and malware writers will set their watches by it, eager to feed at the trough of security flaws and the easy passage into millions of PCs that they guarantee.

This has been the pattern over the last few years for Microsoft, whose Patch Tuesday security events on the second Tuesday of every month is often followed by an Exploit Wednesday the following day, as the software underground moves quickly to reverse engineer the security patches and develop ways to exploit the vulnerabilities they address.

Sometimes, it takes just a few hours for malware writers to get exploit code onto the Web following the public Patch Tuesday disclosure. This has given a new definition to the term "zero day exploit," which originally was coined to refer to vulnerabilities for without patches. The problem is that many customers haven't applied Patch Tuesday patches by Exploit Wednesday.

Microsoft is now saying "enough is enough" to this pattern. On Tuesday it unveiled the new Microsoft Active Protections Program (MAPP) that's designed to give software vendors a head start against the criminally motivated and fast-working hackers.

"Before this program, security software providers waited until the public release of a security update before building protections," Microsoft says in a FAQ accompanying the MAPP announcement. "By obtaining early access to this information, security software providers can deliver protection features to customers more quickly."

The delivery of the MAPP program is a de-facto admission by Microsoft that the security status quo is not working. As a result, the company is entrusting the security community--including developers of antivirus, intrusion detection, intrusion protection, Web and application firewall systems, and so-called "white hat" hackers--to help it protect Windows users.

Put another way, Microsoft is saying that users are not up to the task themselves. It's really not surprising that Windows users don't apply Patch Tuesday patches that very day, but the reality is that it does put them at risk when exploit code goes up for sale the following day, or even earlier. Surveys have confirmed that users are not so good at applying their patches from Microsoft and other vendors.

This is not Microsoft's fault. In recent quarters, Microsoft and other researchers have reported that the rate of security vulnerability discoveries actually decreased in 2007. However, as organized crime makes its way into the business and works to bring increasingly sophisticated development tools and techniques to bear on the task of exploiting security flaws for monetary gain, the underground network of black hat hackers and malware writers has gotten really good at turning flaws into cash, and doing so quickly.

"No one organization can counter online attacks alone," said George Stathakopoulos, general manager of security engineering and communications at Microsoft, in the announcement. "Therefore, we must use the combined strength of the industry, partners, customers, and public organizations to build a more secure environment for everyone.”

Microsoft didn't share a lot details about the criteria needed to gain access into the MAPP program, other than to say they must make security software, have a "large number" of customers, and they must not make attack tools. Interested parties are encouraged to e-mail the company at mapp@microsoft.com.

Presumably, the vendor won't be handing out MAPP passes to anybody claiming to be a security software vendor. After all, as the title of this week's hacking conference shows--as well as the hubbub over the dissemination of details of the recently discovered DNS flaw--there is a somewhat grayish line separating sides in the hacking community, and a fuzzy understanding of what bolsters the Internet's security, and what hurts it.

As a proprietary software vendor, Microsoft's tendency is toward keeping things hush-hush and quietly rolling out fixes when it's ready. This doesn't appear to be working very well anymore, so it's refreshing to see Microsoft try other approaches.

The new "Exploitability Index" should also shine more light on the security work Microsoft is doing. Previously, the software giant used a tiered approach to assessing the potential harm that a vulnerability could do. Patches that fix the most dangerous remotely exploitable problems were deemed "critical," while those that took more work to exploit were given "important" and "moderate" ratings.

When the new Exploitability Index debuts in October, Microsoft will implement a new three-tiered system intended to communicate the likelihood that each vulnerability could be exploited. The three levels--Consistent Exploit Code Likely, Inconsistent Exploit Code Likely, and Functioning Exploit Code Unlikely--will accompany each patch distributed by Microsoft.


RELATED STORIES

Patches? We Don't Need No Stinkin' Patches: Survey

Decline In Vulnerabilities Belies Threat Increase, Microsoft Says in New Security Report

Surf's Up for Web-Based Organized Crime, IBM X-Force Says

Bleak Outlook for Information Security, According to Researchers

In Search Of a More Secure Internet

Security Attacks and Breaches on the Rise

MPack Hacker Tool Claims 10,000 Compromised Web Sites



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
MKS

Meet Your IT Audit and Compliance Demands with MKS

One Seamless Solution for System i and Distributed Application Lifecycle Management

Are you struggling to meet IT audit and compliance demands?
Do you need traceability over software change?

When Pennsylvania Housing Finance Agency (PHFA) needed to achieve compliance, they turned to MKS for traceability over their software change. MKS Integrity enforces their development process and brings end to end traceability to their System i and distributed development operations.

Read the PHFA story.

MKS can help you establish and enforce any software process or workflow, and manage software change from project start to finish. With MKS you can ensure that the application you develop is deployed securely and that only authorized changes go into production.

For auditing and compliance needs, it doesn't get any better than MKS.

For more info, visit http://www.mks.com/itjungle/weareone or call 1 800 613 7535.

Make the Move to MKS now and SAVE!

For a limited time MKS will help you make the move from your existing software change and configuration management solution, with special pricing when you purchase Implementer with MKS Integrity - giving you integrated workflow, complete audit trails and coverage of the application lifecycle as well as a platform to manage both System i and cross-platform development.

Visit the Products section of www.mks.com for more information on Implementer and MKS Integrity.

Click here to request more information on our time limited "change up" offer.

The time is now to make the switch.

Call MKS today at 1-800-613-7535 to discuss your options, and while you're at it,
request a FREE change management process assessment by our team of experts
with over 40 years of experience in the midrange market.

Contact MKS Sales at 1-800-613-7535 or sales@mks.com


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

COMMON:  Join us at the annual 2009 conference, April 26 - April 30, in Reno, Nevada
Storage Guardian:  Remote backup services at a special rate of $8/compressed GB/month
NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40

 

 

IT Jungle Store Top Book Picks

Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
Q&A with IBM's Ross Mauri: Talking Power Systems and Power7

IBM's Q2 Server Sales: Let's Do Some Math

IBM Creates a New Security PTF Group for i Operating Systems

Mad Dog 21/21: Newtonian Economics

Gartner Is Projecting a Decline in IT Hiring This Year

The Linux Beacon
What the Heck Is the Midrange, Anyway?

Intel Talks Up Larrabee X64-Based Graphics Engine

IBM's Q2 Server Sales: Let's Do Some Math

As I See It: Babes in Broadband

Gartner Is Projecting a Decline in IT Hiring This Year

Four Hundred Stuff
Paperless System Brings Unexpected Benefits to Power Company

LogRhythm Partners with PowerTech to Support i OS Log Data

Profound Debuts Graphical Admin Interface for Web-Enabled Apps

Correction: WebFacing Lives On, in HIS and HATS

RJS' WebDocs Gets Google-ized

Big Iron
Unisys: Crunch for the Last of the BUNCH

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Tell Me About Your Exports

So That's What My Database Looks Like

Admin Alert: Moving i5/OS Resources on the Fly

System i PTF Guide
August 2, 2008: Volume 10, Number 31

July 26, 2008: Volume 10, Number 30

July 19, 2008: Volume 10, Number 29

July 12, 2008: Volume 10, Number 28

July 5, 2008: Volume 10, Number 27

June 28, 2008: Volume 10, Number 26

The Unix Guardian
More Power7 Details Emerge, Thanks to Blue Waters Super

HP-UX 11i v3 Update 2 Pricing Redux

IBM Drives Home a Strong Second Quarter Across the Board

The X Factor: The IT Department Matters as Much as the CIO

IT Jobs Grow in the U.S. Despite Economic Woes

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

SafeData
MKS
Guild Companies
Solidcore
Vibrant Technologies


Printer Friendly Version


TABLE OF CONTENTS
What Art Thou, Midori?

Microsoft Works to Put the Clamps on 'Exploit Wednesday'

Yahoo Shareholder Meeting Anti-Climactic

Gartner Is Projecting a Decline in IT Hiring This Year

Microsoft to Buy DATAllegro for Data Warehouse Appliances

But Wait, There's More:

SAP Profits Under Pressure in Q2, Software Prices Get Jacked . . . Yankee Group Says Server Virtualization Adoption Is Accelerating . . . Intel Talks Up Larrabee X64-Based Graphics Engine . . . VMware's Sales Up 54 Percent in Q2, ESX Server 3i Hypervisor Now Free . . . Microsoft Partners with BearingPoint for Compliance . . .

The Windows Observer

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement