Microsoft shifts security strategy

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Conceding that its strategy of patching Windows holes as they emerge has not worked, Microsoft plans next week to outline a new security effort focused on what the company calls "securing the perimeter," a company executive told CNET News.com.

Although Microsoft will continue to devise ways to improve the means by which Windows users apply upgrades, or patches, to their software, the company had realised that too many customers don't upgrade quickly enough to thwart hackers.

"From our side, (it) has been a little naive to think that all of those customers are going to do patches," said Orlando Ayala, Microsoft's former sales chief, who now heads its sales push to small and mid-sized businesses. "It's just hard."

However, recent worm and virus attacks have repeatedly shown that many customers remain vulnerable long after patches have been released, he said.

Ayala declined to detail Microsoft's new approach, or say whether the plans include getting further into the market of providing antivirus software. He did say that part of the effort will be a deeper relationship with firewall providers.

"We are going to start putting more emphasis on what we call securing the perimeter," he said. "That speaks of a deep partnership with the firewall world."

Ayala said that although the company has made some gains with its Trustworthy Computing effort, it is now trying to take a new approach.

"The first question is how can you secure stuff so you don't (let attacks) get in," he said. "It's kind of a shift in the strategy. It's very important; that's all I can say."

The patch treadmill
The Slammer worm that hit companies in January and the recent MSBlast worm highlighted the failure of companies to patch their systems quickly. It's extremely hard for any company to keep up, said Bruce Schneier, chief technology officer for network monitoring service Counterpane Internet Security.

"The patch treadmill is endless -- you have to keep going faster and faster to keep up," he said.

Microsoft executives have recently hinted that a change of course might be needed.

Speaking to a crowd of Silicon Valley executives last month, Microsoft chief executive Steve Ballmer said that the recent security issues represented a threat to innovation. At the time, he said that Microsoft was developing what he called "shield technology."

"The most important technology area we are focused on is shield technology," Ballmer said in the 15 September speech. "We know bad guys keep writing viruses. The goal is to block them before they get on PCs."

At that time, Microsoft declined to comment further on what Ballmer meant.

Finding a way to deal with the avalanche of patches that come in, not just from Microsoft but from other software makers, has become a key focus of information-technology managers, said Ryan McGee, director of product marketing for McAfee System Protection Solutions at security and antivirus company Network Associates.

"This is a topic of conversation in every customer conversation that we have," he said. "We talk about how to mitigate the vulnerabilities that are in the environments because they haven't been able to patch."

The recent MSBlast worm that hit companies in August and September probably infected more than a million computers. From the time information about the vulnerability was released to the start of the attack, companies had 26 days to patch their systems. And the times are decreasing, according to a recent study. For companies with tens of thousands of systems, keeping up with the race is hard, McGee said.

"We hear customers telling us there is a problem," he said, adding that several companies offer patch management automation as a solution. "I wish I were announcing a (patch management) product or acquisition because it's a market where we could make money."

Many companies are already in the market of detecting and cataloging vulnerable computer and network devices and then automating patching. A recent study by one such company, Qualys, found that a significant portion of security vulnerabilities remain on computers connected to the Internet.

Those vulnerabilities are making selling patch management systems to large companies an easy prospect, said Mark Shavlik, chief executive of patch automation firm Shavlik Technologies, especially when the companies are faced with a serious widespread flaw such as the vulnerability that allowed MSBlast to spread.

"Our sales went up eight times between July and September -- that's a pretty big spike," he said. "None of those people were doing patch management before. MS03-026 (the advisory highlighting the MSBlast flaw) comes out; that changed the market for us."

Shavlik wasn't sure that Microsoft is headed in the right direction, especially if the focus is too heavily on the intersection of a company's network and the Internet. "If you go to a perimeter defence, and a worm slips by your perimeter, it will compromise your entire network," he said.

Coming in the middle of the second year of Microsoft's Trustworthy Computing Initiative, the move may indicate that more shifts are ahead for the software giant. Ayala did acknowledge that Microsoft needs to do better than it has done with its Trustworthy Computing effort.

Perhaps the biggest incentive, said Counterpane's Schneier, is diverting the bad publicity that major attacks heap on Microsoft. As long as the company continues to be attacked by online vandals and scofflaws, Microsoft will have to continue pushing security, he said.

"To Microsoft, the threat is bad publicity, and they are going to produce a security system that deals with the threat," he said.

Talkback

One way in which users ould be able to apply patches more easily is if they could easily be downloaded for later installation - I have an unpatched home PC because it would take too long to download. However, I'm on a fast LAN at work so could burn a CD easily (this could also apply to internet cafe users and people with friends on broadband)

via Facebook 2 October, 2003 09:42
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

9 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

17 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

18 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

19 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

21 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

22 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

23 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

1 day ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint