How To Keep Up With Security Patches Eric Schultze Security Strategies Microsoft.

Slides:



Advertisements
Similar presentations
Configuring Windows to run Dr.Web scanner remotely.
Advertisements

A Technical Overview of Microsoft Forefront Client Security (FCS) Howard Chow Microsoft MVP.
SAGE-AU Adelaide Windows Update Services Michael Kleef IT Pro Evangelist Microsoft Corporation Level 200.
Microsoft Security Resources. URL’s for this talk All URL’s mentioned in this talk can be found here: All URL’s mentioned in this talk can be found here:
Patch management with ZenWorks James Dore, IT Officer, New College /
Office 365 ProPlus: Expanding Your Deployment Skills Yoni Kirsh Ben Fletcher OSS301.
1 Secure Your Business PATCH MANAGEMENT STRATEGY.
Microsoft Baseline Security Analyzer INLS 187 Security Software Presentation by Hinár György Polczer
Patching MIT SUS Services IS&T Network Infrastructure Services Team.
A Tour of System Center Configuration Manager Adam Duffy Edina Public Schools.
Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches.
Microsoft ® Application Virtualization 4.5 Infrastructure Planning and Design Series.
Patch management using Microsoft Software Update Service 1.0 SP1 Chris Hughes, Systems Architect Warrington College of Business
Windows Anti-virus and Security WNUG Meeting
Wally Mead Senior Program Manager Microsoft Corporation Session Code: MGT303.
WIN-B331 Get a consistent, personal Windows experience that matches your unique work style Easy for IT to deliver personal, user-defined experiences.
11 MAINTAINING THE OPERATING SYSTEM Chapter 5. Chapter 5: MAINTAINING THE OPERATING SYSTEM2 CHAPTER OVERVIEW Understand the difference between service.
OSP219. Experience Office as it was meant to be… without the complexity of setting up servers.
Group Policy in Microsoft Windows Active Directory.
IT:Network:Microsoft Applications
Module 16: Software Maintenance Using Windows Server Update Services.
16.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 16: Examining Software Update.
Choose and Book Installing Security Broker (IA) client.
11 MAINTAINING THE OPERATING SYSTEM Chapter 5. Chapter 5: MAINTAINING THE OPERATING SYSTEM2 CHAPTER OVERVIEW  Understand the difference between service.
Patch Management and HFNetChkPro 4.0
Wally Mead Senior Program Manager Microsoft Corporation.
Managing CERN Desktops with Systems Management Server (SMS 2003) Michel Christaller Internet Services Group Department of Information Technology CERN May.
SOE and Application Delivery Gwenael Moreau, Abbotsleigh.
4/20/2017 6:38 PM © 2004 Microsoft Corporation. All rights reserved.
Cisco Unity & Unity Connection Server Updates Wizard TOI Josh Rose UCBU Engineering May 17, 2007.
IT:Network:Microsoft Server 2 Chapter 27 WINDOWS SERVER UPDATE SERVICES.
Benjamin Lavalley, Sr. Product Marketing Manager Kaseya 2 Upgrade Review.
Software Licensing, Made Simple SELECT Server XM Edition
Microsoft Installer Technologies and patch management approaches.
Using the WDK for Windows Logo and Signature Testing Craig Rowland Program Manager Windows Driver Kits Microsoft Corporation.
Tim Vander Kooi Systems
Terry Henry IS System Manager, SharePoint SME Micron Technology Inc.
Patch Management Only part of the solution….. Bob Isaak Mar 04, 2004.
Managing and Monitoring Windows 7 Performance Lesson 8.
The Microsoft Baseline Security Analyzer A practical look….
SMS 2003 Deployment and Managing Windows Security Rafal Otto Internet Services Group Department of Information Technology CERN 26 May 2016.
Windows 2003 Installation/Upgrade and Update. Checking Compatibility Supported Upgrade paths Using the MS Windows Upgrade Advisor HCL (Hardware Compatibility.
1 Using Silent Install Scripts to Deploy Software to MS Windows PCs. Larry Carpenter, P.E. CAx Administrator / FE Analyst Siemens Healthcare Molecular.
Managing Windows Software & Updates SUS Server MS Baseline Security Analyzer Software and Group Policy Paul “The Yellow Dart” Peterson University of Minnesota.
Paul Butterworth Management Technology Architect
CN2140 Server II Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Martin Sjölin LISA NT 1999, 1 State Driven Software Installation for Windows NT Martin Sjölin, WDR
Microsoft Management Seminar Series SMS 2003 Change Management.
Rob Davidson, Partner Technology Specialist Microsoft Management Servers: Using management to stay secure.
Vlad Mazek Own Web Now Corp CEO, MCSE, MCSA, CISSP (877) Portions reproduced with permission from Dean Calvert.
DST 2007 ██ Areas that observe daylight saving time ██ Areas that once observed daylight saving time ██ Areas that have never observed daylight saving.
Virtualization Technology and Microsoft Virtual PC 2007 YOU ARE WELCOME By : Osama Tamimi.
© 2008 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED,
Wally Mead Senior Program Manager Microsoft Corporation Session Code: MGT305.
Microsoft EMEA Retail Technology Conference 2004 Microsoft EMEA Retail Technology Conference 2004 System Management in Store Willem Haring
How to Deploy Office XP and Windows XP With One Desktop Touch Liz Levitt Desktop Solution Specialist Microsoft Corporation.
Internet Explorer 7 Updated Advice for the NHS 04 February 2008 Version 1.3.
Professional Plus 2013 Microsoft is committed to keep providing additional value for Office 365 subscribers PowerMap Lync Mobile Client Updates February.
Third-Party Patch Management using SCCM 2012 R2 SP1, SCUP 2011, and iExpress Chris Nienaber.
Managed by UT-Battelle for the Department of Energy System Center Configuration Manager at ORNL National Laboratories Information Technology Summit 2008.
Information About Microsoft’s August 2004 Security Bulletins August 13, 2004 Feliciano Intini, CISSP, MCSE Security Advisor Premier Security Center Microsoft.
Lesson 19: Configuring and Managing Updates
Extended Operating System Support
System Center 2012 Configuration Manager
5/19/2018 7:00 AM © 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
StratusLab Tutorial (Bordeaux, France)
BMC BladeLogic Windows Patching Troubleshooting
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
Chapter 10: Supporting and Maintaining Desktop Applications
Implementing Security Patch Management
Presentation transcript:

How To Keep Up With Security Patches Eric Schultze Security Strategies Microsoft

Questions How do I know if I’m up to date on patches? How do I know if I’m up to date on patches? How do I know when a new patch is released? How do I know when a new patch is released? How do I know that the patch is valid on my system? How do I know that the patch is valid on my system? How can I deploy patches to all my machines? How can I deploy patches to all my machines? What is Microsoft doing to make it easier to assess and deploy patches? What is Microsoft doing to make it easier to assess and deploy patches?

Patch Process New Patch Notification New Patch Notification Host and Network Assessment Host and Network Assessment Deployment Deployment Validation Validation

Notification How do I know when new security patches are available? How do I know when new security patches are available? Security Bulletin Notification Service Security Bulletin Notification Service Windows Update Windows Update Client Update Notification Applet Client Update Notification Applet HFNetChk HFNetChk

How can I tell which machines need patches? HFNetChk HFNetChk Can be run against Windows NT 4, Windows 2000, Windows XP Can be run against Windows NT 4, Windows 2000, Windows XP Evaluates patch status for OS, IIS, IE, and a limited amount of SQL 7 and Evaluates patch status for OS, IIS, IE, and a limited amount of SQL 7 and See KB article Q for more info and download location See KB article Q for more info and download location

HFNetChk Demo

How Does HFNetChk Work? 1. Downloads signed CAB file (containing XML data) from microsoft.com 1. May also use a local copy of the XML file from a file or http share 2. Tool Version Check 3. Language \ OS \ SP \ Application check 4. Identifies all relevant security patches for OS \ SP \ App

MSSecure.XML

How Does HFNetChk Work? For each applicable hotfix: 5. Compare registry key from XML file to registry key on the system If reg key does NOT exist, file is determined to be NOT installed If reg key does NOT exist, file is determined to be NOT installed Reg key check can be bypassed with the –z switch Reg key check can be bypassed with the –z switch

How Does HFNetChk Work? 6. If registry key DOES exist*, compare file version information from XML file to files on system 7. If registry key DOES exist*, compare file checksum information from XML file to files on system * Or if registry checks were bypassed

MSSecure.XML

How Does HFNetChk Work? If either the file version and/or the checksum does NOT match for any file, the patch is considered NOT installed If either the file version and/or the checksum does NOT match for any file, the patch is considered NOT installed (a Warning is given if the fileversion is greater than expected) (a Warning is given if the fileversion is greater than expected) In every instance file versions and checksums are evaluated! In every instance file versions and checksums are evaluated!

New MSSecure Schema Patch details for all languages Patch details for all languages Download URL for each patch for each language Download URL for each patch for each language hotfix installer engine and related switches hotfix installer engine and related switches MD5 and SHA1 file hashes MD5 and SHA1 file hashes Specific file location (relative and/or system variable) Specific file location (relative and/or system variable) 56 bit vs 128 bit crypto, mulit-proc vs. single-proc, 32 bit vs 64 bit architecture 56 bit vs 128 bit crypto, mulit-proc vs. single-proc, 32 bit vs 64 bit architecture Severity data Severity data CVE data CVE data reboot actions reboot actions

Deployment How do I push patches to the machines that need them? How do I push patches to the machines that need them? SMS SMS Third party tools Third party tools Active Directory / Group Policy Active Directory / Group Policy

SMS

HFNetChkPro

HFNetChkPro

HFNetChkPro

Group Policy and MSI Create MSI package for hotfix Create MSI package for hotfix Future MS hotfixes may include MSI packages Future MS hotfixes may include MSI packages Use third party MSI creator Use third party MSI creator InstallShield, SMS, etc. InstallShield, SMS, etc. Create Group Policy with Computer Settings for Software Installation Create Group Policy with Computer Settings for Software Installation

Group Policy and MSI

Corporate Windows Update Allows Corporations to host their own Windows Update Server. Allows Corporations to host their own Windows Update Server. CorpWU Server downloads catalogs and patches from Microsoft CorpWU Server downloads catalogs and patches from Microsoft Administrator chooses which ones to make available on corpnet Administrator chooses which ones to make available on corpnet New WU clients are configured (via Group Policy or Reg key) to perform WU operations against CorpWU Server New WU clients are configured (via Group Policy or Reg key) to perform WU operations against CorpWU Server

Corporate Windows Update Clients can also be configured via Group Policy to autodownload and apply the patches within a given period of time, should the system owner not do it on their own. Clients can also be configured via Group Policy to autodownload and apply the patches within a given period of time, should the system owner not do it on their own.

What else is Microsoft doing? Focus on Trustworthy Computing from BillG Focus on Trustworthy Computing from BillG Rollup Packages Rollup Packages Cumulative Cumulative Every two months for latest Service Pack Every two months for latest Service Pack May be released as MSI May be released as MSI Increase in No-Reboot patches Increase in No-Reboot patches Additional Tools like HFNetChk Additional Tools like HFNetChk

Contact Info