<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CoreTrace WhiteSpace&#187; CoreTrace WhiteSpace</title>
	<atom:link href="http://www.coretraceblogs.com/tag/patching/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.coretraceblogs.com</link>
	<description>The Application Whitelisting and Security Weblog</description>
	<lastBuildDate>Fri, 30 Jul 2010 14:33:34 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Window&#8217;s crashes linked to rootkits after problems with latest patch</title>
		<link>http://www.coretraceblogs.com/2010-02/windows-crashes-linked-to-rootkits-after-problems-with-latest-patch/</link>
		<comments>http://www.coretraceblogs.com/2010-02/windows-crashes-linked-to-rootkits-after-problems-with-latest-patch/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 19:03:52 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[endpoint protection]]></category>
		<category><![CDATA[patching]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1297</guid>
		<description><![CDATA[Growing evidence suggests that a rootkit infection was *one* of the culprits behind last week&#8217;s Blue Screen of Death incident that caused countless Windows PCs to lock down after installing several Microsoft security patches.  While many follow-up articles have focused on the malware infection that caused the problem, including Robert Westervelt&#8217;s SearchSecurity.com article, &#8220;Windows [...]]]></description>
			<content:encoded><![CDATA[<p>Growing evidence suggests that a rootkit infection was *one* of the culprits behind last week&#8217;s Blue Screen of Death incident that caused countless Windows PCs to lock down after installing several Microsoft security patches.  While many follow-up articles have focused on the malware infection that caused the problem, including Robert Westervelt&#8217;s SearchSecurity.com article, <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1381423,00.html?track=sy160&#038;utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+techtarget%2FSearchsecurity%2FSecurityWire+%28SearchSecurity+%3A+Security+Wire+Daily+News%29" target="_blank">&#8220;Windows blue screen may be result of rootkit infection,&#8221;</a> from an endpoint security standpoint, most seem to be missing the point. And that point is even though malware may be causing this problem, rushed patching is a process that can always cause problems.<span id="more-1297"></span></p>
<p>As I mentioned in last week&#8217;s entry, <a href="http://www.coretraceblogs.com/2010-02/latest-microsoft-patch-illustrates-the-dilemma-and-dangers-of-fire-drill-patching/" target="_blank">&#8220;Latest Microsoft patch illustrates the dilemma and dangers of fire drill patching,&#8221;</a> relying on antivirus defenses to protect endpoints ties organizations to fire drill software patching. Reactive software application patching will never provide the level of protection today&#8217;s companies need to adequately protect their networks against harmful malware. As Mr. Westervelt goes on to write:</p>
<blockquote>
<p>Rootkits are fairly common. They are installed by attackers who first gain access to the machine by exploiting a vulnerability. Once inside, the rootkit is deployed giving the attacker the ability to mask intrusion and gain root or privileged access to the computer. It can also be a package of spyware programs that monitor traffic and record keystrokes. Antivirus vendors typically have trouble detecting rootkits.</p>
</blockquote>
<p>What these recent stories point out is that malware infections on these devices only highlights the fact that existing desktop security isn&#8217;t working properly. Why else are these companies regularly patching?  The desktop security paradigm of antivirus and patching simply isn&#8217;t working.</p>
<p>Unfortunately, what we&#8217;re seeing is that patching itself is also causing problems with their systems. Organizations are better off focusing on ways to effectively stop Web-malware and malicious code from deploying in the first place than aimlessly reacting to cyber criminals exploiting the known and unknown vulnerabilities within their network.  Playing catch up with more patches is not only a losing proposition for IT security professionals, it seems to be compounding the problem.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-02/windows-crashes-linked-to-rootkits-after-problems-with-latest-patch/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Latest Microsoft patch illustrates the dilemma and dangers of fire drill patching</title>
		<link>http://www.coretraceblogs.com/2010-02/latest-microsoft-patch-illustrates-the-dilemma-and-dangers-of-fire-drill-patching/</link>
		<comments>http://www.coretraceblogs.com/2010-02/latest-microsoft-patch-illustrates-the-dilemma-and-dangers-of-fire-drill-patching/#comments</comments>
		<pubDate>Fri, 12 Feb 2010 16:02:01 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[whitelisting]]></category>
		<category><![CDATA[patching]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1281</guid>
		<description><![CDATA[This week I kicked off our Planet Antivirus challenge with a blog entry highlighting the top 5 failures of antivirus. My fifth point highlighted the fact that relying on antivirus resulted in a reliance on fire drill patching as a result:

Relying on antivirus ties companies to fire drill software patching &#8212; The side effect of [...]]]></description>
			<content:encoded><![CDATA[<p>This week I kicked off our <a href="http://www.planet-antivirus.com/" target="_blank">Planet Antivirus</a> challenge with a blog entry highlighting the <a href="http://www.coretraceblogs.com/2010-02/the-top-5-failures-of-antivirus/" target="_blank">top 5 failures of antivirus</a>. My fifth point highlighted the fact that relying on antivirus resulted in a reliance on fire drill patching as a result:</p>
<blockquote>
<p>Relying on antivirus ties companies to fire drill software patching &#8212; The side effect of relying on antivirus to protect endpoints is that companies are now tied to reactive software application patching as well. Because we can’t trust our antivirus software to protect the endpoint, we also must remain constantly aware and vigilant about identifying and fixing vulnerabilities in our applications on the endpoint. The resulting combination of rushed patches and signatures is a significant drain on the human resources of an organization.</p>
</blockquote>
<p>It&#8217;s rare that such a post has supporting evidence appear just days after it is published, but this week, that is exactly what happened. It was reported this week that a Windows XP security update resulted in the notorious Blue Screen of Death (BSOD), locking up many users’ Windows XP PCs. In the article, <a href="http://www.computerworld.com/s/article/9155419/Windows_patch_cripples_XP_with_blue_screen_users_claim" target="_blank">&#8220;Windows patch cripples XP with blue screen, users claim,&#8221;</a> hundreds of Windows users expressed their frustrations on the company&#8217;s support forum throughout the week.<span id="more-1281"></span></p>
<p>The problem appears to have originated with one of the 13 updates the company issued on Tuesday to patch a 17-year-old kernel bug in all 32-bit versions of Windows. After users updated and tried to restart their PCs, they ran into the infamous Blue Screen.</p>
<p>Unfortunately, this is yet another example of the growing problems organizations experience when relying on patches to secure their network and the dangers of rolling out patches quickly. This isn&#8217;t an isolated case as the article points out:</p>
<blockquote>
<p>This was not the first time that a Microsoft update has incapacitated Windows PCs. Two years ago, a set of updates for Vista sent an unknown number of machines into an endless series of reboots. Similar problems stymied users who tried to upgrade to Windows XP Service Pack 3 (SP3) in May 2008, and others attempting to upgrade from Vista to Windows 7 last October.</p>
</blockquote>
<p>There was once a time when patching was an effective way of dealing with security flaws and vulnerabilities within their operation system. However, in today&#8217;s world the sheer volume of new patches combined with the time is takes to disclose a vulnerability, create and distribute the updated code, systems are practically sitting ducks to new malware and viruses ready to exploit a network at every opportunity. In addition, when the patch finally comes out, smart organizations take the time to ensure that the fix itself won&#8217;t cause problems with their systems. That&#8217;s where a solution such as application whitelisting can help. Whitelisting gives organizations time to test patches and roll them out on a regular schedule avoiding fire drill patching and more time exposed to attacks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-02/latest-microsoft-patch-illustrates-the-dilemma-and-dangers-of-fire-drill-patching/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The top 5 failures of antivirus</title>
		<link>http://www.coretraceblogs.com/2010-02/the-top-5-failures-of-antivirus/</link>
		<comments>http://www.coretraceblogs.com/2010-02/the-top-5-failures-of-antivirus/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 15:43:59 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[blacklisting]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[whitelisting]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1240</guid>
		<description><![CDATA[I truly believe that 2010 is a turning point in endpoint security. The old antivirus model has reached the end of its practical usefulness and the disadvantages of an approach with a foundation of blacklisting far outweigh its benefits. Operation Aurora and the attacks against major online brands perfectly illustrates the failure of our old [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.coretraceblogs.com/2010-02/the-top-5-failures-of-antivirus/back-to-square-one-signpost/" rel="attachment wp-att-1253"><img src="http://www.coretraceblogs.com/wp-content/uploads/2010/02/iStock_failure_sign-303x201.jpg" alt="" title="The top 5 failures of antivirus" width="303" height="201" class="alignright size-medium wp-image-1253" /></a>I truly believe that 2010 is a turning point in endpoint security. The old antivirus model has reached the end of its practical usefulness and the disadvantages of an approach with a foundation of blacklisting far outweigh its benefits. Operation Aurora and the attacks against major online brands perfectly illustrates the failure of our old paradigm to protect endpoints.</p>
<p>Later this week, we are launching a fun (and funny) awareness campaign, called Planet Antivirus, highlighting the weaknesses of antivirus and focusing on the need to completely rethink our approach to how we defend endpoints. Today I am kicking this campaign off by highlighting the top five failures of antivirus technology:<span id="more-1240"></span></p>
<ul>
<li>
<p><strong>Antivirus is a performance hog</strong> &#8212; One of the most common complaints we hear about antivirus is its performance impact. This can weigh heavier on the minds of IT managers than its problems with catching new threats. A perfect example of this is a <a href="http://reviews.cnet.com/Labs/4520-6603_7-5020816-10.html" target="_blank">description from CNET Labs</a> on how they test antivirus:</p>
<blockquote>
<p>&#8220;Antivirus programs are designed to detect and intercept harmful files downloaded to your computer. In order to monitor incoming files, however, antivirus programs &#8212; like all applications &#8212; need to use system resources. The degree to which an antivirus program detrimentally affects a system&#8217;s performance varies from one application to another. CNET Labs tests three areas of antivirus application performance: how deep-file virus scanning impacts overall system performance, how quickly files can be scanned for viruses, and how system boot time is affected by the antivirus program. We also report on how effective the antivirus programs are at identifying viruses by citing the studies of established industry authorities.&#8221;</p>
<p>It is telling that the majority of their test is concerned with how antivirus detrimentally impacts system performance. The effectiveness of the antivirus solution is almost an afterthought.</p>
</blockquote>
</li>
<li>
<p><strong>Antivirus is an after the fact cleaner and it doesn&#8217;t even do that well</strong> &#8212; The simple fact is that antivirus can&#8217;t protect you from getting infected. This is indisputable and has been empirically proven time and again. So why do we still use it? One reason people continue to use antivirus is that it is used to identify infections and to clean up the mess. Unfortunately it doesn&#8217;t even do that well. If you are infected by a particularly nasty piece of malware, many times the best option you have is to completely rebuild your system. There is a great post on this on the Cornell Information Technology site titled, <a href="http://www.cit.cornell.edu/security/respond/wipeclean.cfm" target="_blank">&#8220;Rebuilding Your System Is the Safest Road to Recovery after a Malware Attack,&#8221;</a> that does a good job of making this case:</p>
<blockquote>
<p>&#8220;<strong>Dangerous software hides from repair tools</strong>: The IT Security Office recommends formatting one&#8217;s hard drive followed by a complete software reinstallation in response to a system compromise. Modern malware relies on rootkits to hide itself from antivirus software and administrator analysis. Rootkits use a variety of techniques, such as executable encryption, alternate data streams, innocently-named files or registry keys, concealment in system restore points or patch clusters, or the use of portions of the disk not conventionally accessible to the operating system. These elaborate, and effective, concealment methods make it difficult or impossible to return a computer to a safe, functional state. Often removal of the malware can render the system nonfunctional. Worse yet, incomplete or ineffective removal means the attacker may regain control of the computer.</p>
<p>strong>Complete reinstallation is necessary: A reinstallation includes not only the operating system, but also application software. It is important to realize that any application software currently on the computer may be tainted by the attacker and only trusted original sources should be used for reinstallation.&#8221;</p>
</blockquote>
</li>
<li>
<p><strong>Antivirus was designed to address a different threat</strong> &#8212; Despite the addition of heuristics and behavioral models to detect variants of malware, the fact remains that blacklisting is the foundation of antivirus and it was designed to address a different threat than today&#8217;s malware. Antivirus originated to protect against propagating threats. These threats either propagated through the sharing of disks and files by individual users or were self propagating worms that identified weaknesses in networked computers and subsequently infected vulnerable systems. Blacklisting in this model was feasible and effective because it was both easy to collect samples of the malware and protect against a limited set of threats.</p>
<p>Today&#8217;s threats are different. Today, online crime hinges on the combination of social engineering and vulnerability exploitation that allows the attacker to place a custom piece of malware on the targeted system. This is a much harder problem to solve by blacklisting. The attacks can be customized for uniquely targeted online businesses or groups of businesses with software that would elude even the most sophisticated antivirus solution. My main concern if I was Google or any of the other companies targeted in Operation Aurora wouldn&#8217;t be what data they stole from me, but what malware they left behind to use at another time. Most likely they will have to resort to reinstalling those systems as I mentioned in the previous point.</p>
</li>
<li>
<p><strong>Antivirus updates are too frequent and can cause problems</strong> &#8212; In order to keep up with the exploding world of malware most antivirus applications issue updates at a very regular interval. This can be as frequently as an update a day in some cases. The problem with this is not only does it require regular distribution of these updates to all endpoints with its corresponding performance impact, but the frequency of updates also means that problems from the updates are more likely to occur. The result of a decrease in reliability of signature updates means that many organizations try to test updates before they roll out the new signatures. This simply isn&#8217;t practical. The frequency of signature updates means that testing won&#8217;t work or even be completed before the next update arrives. Organizations either need to revert to a less frequent update schedule to allow testing, potentially extending the time they are exposed to a new threat, or they need to simply trust that the update files from their antivirus company won&#8217;t cause problems. Neither of these options is optimal.</p>
</p>
</li>
<li>
<p><strong>Relying on antivirus ties companies to fire drill software patching</strong> &#8212; The side effect of relying on antivirus to protect endpoints is that companies are now tied to reactive software application patching as well. Because we can&#8217;t trust our antivirus software to protect the endpoint, we also must remain constantly aware and vigilant about identifying and fixing vulnerabilities in our applications on the endpoint. The resulting combination of rushed patches and signatures is a significant drain on the human resources of an organization.</p>
</li>
</ul>
<p>2010 needs to be the year that we begin a healthy discussion of completely re-evaluating the approaches we use to protect our endpoints.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-02/the-top-5-failures-of-antivirus/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Top Endpoint Security Stories for November 2009</title>
		<link>http://www.coretraceblogs.com/2009-12/top-endpoint-security-stories-for-november-2009/</link>
		<comments>http://www.coretraceblogs.com/2009-12/top-endpoint-security-stories-for-november-2009/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 20:09:56 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[CoreTrace]]></category>
		<category><![CDATA[endpoint protection]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=957</guid>
		<description><![CDATA[November was a busy month for security stories. The month kicked off with more stories of massive security patches from both Microsoft and Apple leaving me to wonder when the patching madness will ever end. Windows 7 was found to have a flaw that allows denial of service attacks. Internet Explorer v7 (IE7) even made [...]]]></description>
			<content:encoded><![CDATA[<p>November was a busy month for security stories. The month kicked off with more stories of massive security patches from both Microsoft and Apple leaving me to wonder when the patching madness will ever end. Windows 7 was found to have a flaw that allows denial of service attacks. Internet Explorer v7 (IE7) even made it into the news with the latest vulnerability, but I question efforts to patch an aging application, why not just upgrade or use <a href="http://www.mozilla.com/en-US/firefox/firefox.html" target="_blank">Firefox</a>? If they aren&#8217;t willing to upgrade, do people really think they will patch IE7?</p>
<p>Without further delay, here are the stories that caught my eye in November:<span id="more-957"></span></p>
<ul>
<li class="margin_bottom_1em"><strong>Apple issues a massive security patch of its own</strong> – In November <a href="http://threatpost.com/en_us/blogs/apple-plugs-58-holes-monster-mac-os-x-update-110909" target="_blank">Apple issued a patch that fixed 58 holes</a> as reported by Threatpost. The days of Apple being immune to security compromise are over. The combination of phishing and browser based attacks should make Mac users concerned and will soon drive security solutions adoption on those systems.</li>
<li class="margin_bottom_1em"><strong>Microsoft is back with it&#8217;s own large security patch</strong> – Microsoft fixed <a href="http://www.computerworlduk.com/technology/operating-systems/windows/news/index.cfm?newsid=17501" target="_blank">15 separate vulnerabilities with 6 security updates </a>in November. This is the same old story as previous months, but at least it wasn&#8217;t the record 13 updates hit in October.</li>
<li class="margin_bottom_1em"><strong>Microsoft reported an increase in worm infections, but decrease in scareware antivirus</strong> – Worm infections were up over 98% since the last Microsoft Security Intelligence report and it appears that Conficker bears a good part of the blame. Researchers believe that it is still being spread by USB keys with autoexecute capabilities. Scareware numbers are down where a user is tricked into visiting a site that says they are infected and then prompted to download &#8220;protection&#8221; from the malware.</li>
<li class="margin_bottom_1em"><strong>More news of botnet operators utilizing social networks to avoid detection</strong> – Searchsecurity.com reported that <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1373974,00.html?track=sy160" target="_blank">botnet writers are turning to Google and social networks</a>. Popular social networking sites like Facebook and Twitter are increasingly prominent in security news for both spreading infection and providing a means of command and control for organized malicious software writers.</li>
<li class="margin_bottom_1em"><strong>Four people were sentenced in the UK for attacks on online banks</strong> – This is something I would like to see more of. It is a rare occurrence when cyber criminals are actually tracked down and brought to justice. Last month <a href="http://www.itworld.com/security/84838/uk-hails-first-cybercrime-cooperation-banks" target="_blank">four individuals who were syphoning money from online accounts were caught and sentenced</a>. </li>
<li class="margin_bottom_1em">CSO online had a nice detailed story about the fight against botnets – CSO published a nice seven page story <a href="http://www.csoonline.com/article/507936/The_Botnet_Hunters_">about the individuals and organizations who research and combat botnets</a>. It&#8217;s an interesting and informative read.</li>
<li><strong>Windows 7 is revealed to have flaw that allows DoS attacks</strong> &#8211; <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1374572,00.html?track=sy160&#038;utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+techtarget%2FSearchsecurity%2FSecurityWire+%28SearchSecurity+%3A+Security+Wire+Daily+News%29" target="_blank">A flaw in the OSs Server Message Block (SMB) could be used to crash the system</a> and could be activated when a user visits a malicious website.</li>
</ul>
<p>There were several other interesting stories, but the fact remains that endpoints are under attack and we are in a continual catch up game with our current endpoint security.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2009-12/top-endpoint-security-stories-for-november-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft prepares for biggest patch Tuesday Ever &#8211; Endpoint security has never been worse</title>
		<link>http://www.coretraceblogs.com/2009-10/microsoft-prepares-for-biggest-patch-tuesday-ever-endpoint-security-has-never-been-worse/</link>
		<comments>http://www.coretraceblogs.com/2009-10/microsoft-prepares-for-biggest-patch-tuesday-ever-endpoint-security-has-never-been-worse/#comments</comments>
		<pubDate>Mon, 12 Oct 2009 23:04:58 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[endpoint protection]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[whitelisting]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=641</guid>
		<description><![CDATA[Tomorrow Microsoft will release an operating system patch that represents the largest number of system fixes in Microsoft history. PCWorld gave the details in a post updated yesterday:

Microsoft says it will deliver its largest-ever number of security updates on Tuesday to fix flaws in every version of Windows, as well as Internet Explorer (IE), Office, [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.coretraceblogs.com/wp-content/uploads/2009/10/iStock_bandaid-298x227.jpg" alt="Microsoft prepares for largest patch tuesday ever" title="Microsoft prepares for largest patch tuesday ever" width="298" height="227" class="alignright size-medium wp-image-647" />Tomorrow Microsoft will release an operating system patch that represents the <a href="http://www.pcworld.com/article/173440/brace_yourself_microsoft_readies_record_setting_patch_tuesday.html?tk=rss" target="_blank">largest number of system fixes in Microsoft history</a>. PCWorld gave the details in a post updated yesterday:</p>
<blockquote>
<p>Microsoft says it will deliver its largest-ever number of security updates on Tuesday to fix flaws in every version of Windows, as well as Internet Explorer (IE), Office, SQL Server, important developer tools and the enterprise-grade Forefront Security client software.<span id="more-641"></span></p>
<p>Among the updates will be the first for the final, or release to manufacturing, code of Windows 7, Microsoft&#8217;s newest operating system.</p>
<p>The company will ship a total of 13 updates next week, eight of them pegged &#8220;critical,&#8221; the highest threat ranking in its four-step scoring system, beating the previous record of 12 updates shipped in February 2007 and again in October 2008.</p>
</blockquote>
<p>Still unknown is whether this patch will fix the critical SMB2 problem that I referenced in last week&#8217;s <a href="http://www.coretraceblogs.com/2009-10/top-endpoint-security-stories-september-2009/" target="_blank">September Endpoint Security Stories</a> post.</p>
<p>What is ironic is that we are setting records for security patches when Microsoft has made such a large deal about the enhancements of security in Vista and soon to be released Windows 7. Identity theft is at an all time high, botnet infections are rampant, all in all online crime has never been more organized and the individual endpoint is the lynchpin of online criminals arsenal.</p>
<p>The reality is that endpoint security has never been worse. Patching and blacklist antivirus solutions are broken. Gartner and many others have repeatedly called for <a href="http://www.coretraceblogs.com/2009-09/time-to-start-over-on-desktop-security/" target="_blank">starting over on desktop security</a>. We agree and we believe that application whitelisting is absolutely critical in a transition to a more rational approach to securing the endpoint.</p>
<p>There are currently two main obstacles that must be addressed for whitelisting to become more prevalent. First, a solution must not require a clean initial system and it should not disrupt operations when it is deployed. Second, there needs to be a process that allows users to make application updates and system changes both without involving IT and without putting their system at risk. <a href="http://www.coretrace.com/products/default.aspx" target="_blank">Bouncer</a> addresses both. We encourage organizations to reexamine their approach to desktop security and look at how application whitelisting can help them start over.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2009-10/microsoft-prepares-for-biggest-patch-tuesday-ever-endpoint-security-has-never-been-worse/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
