Bit9

Skip Navigation
 

Enterprise Application Whitelisting

Current Articles | RSS Feed RSS Feed

Are You Ready for Enterprise Application Whitelisting? Part 5

Posted by Brian Gladstein on Thu, Apr 03, 2008
  | Share on Twitter Twitter | Buzz This  Google Buzz | Submit to Digg digg it |  Share on LinkedIn LinkedIn 

Welcome to my final posting in a series entitled "Are You Ready for Enterprise Application Whitelisting?" I hope these little snippets have been helpful and have assisted you in determining if your IT organization is mature enough to consider whitelisting - and if you would be able to take advantage of its benefits.

 

Today's post is one that I've seen many IT groups struggle with first-hand. It has to do with the complexity of modern security products and how much training they seem to require today. Lots of IT administrators simply are not equipped to effectively manage these overly-complicated security policies. Which leads us straight to the question:

 

Question 5: Is the security expertise required by endpoint protection suites too much?

 

Think about that one for a minute and ask yourself a few questions:

 

  • Do you run an advanced desktop security suite that includes antivirus, personal firewall, HIPS, and other components?
  • If not - why? What's holding you back?
  • If so - are you really using all the components?
  • If you aren't using everything - why did you buy such a comprehensive piece of software and not use it to full effectiveness?

 

The answer is almost always that most IT organizations simply are not ready or don't contain the skillsets to run and operate an advanced security tool that forces you to define cross-product policies that account for malicious behavior patterns and multi-layered protection schemes.

 

IT organizations have always been great at deploying AV because all they had to do was make sure that the AV packages was installed and up-to-date. They didn't have to decide what was secure and what wasn't.

 

But operating a HIPS solution or even a personal firewall today requires the operations team to be making decisions about the security policy that will have dramatic impacts on the ability for the organization to actually protect its systems and its data.

 

Usually what happens is the IT group gets one of these advanced desktop security products and then doesn't deploy it. So they've increased costs and decreased security, all at the same time.

 

If you are one of these people then you are absolutely ready to look at application whitelisting. Becuase with whitelisting, there are no complex security policies to understand. Simply choose the applications that your business should be running. Nothing else gets in.

 

If an application is found to contain a vulnerability - ban it. If an application fails to pass some basic security screens, stop it from being able to run. If you don't know what an application is, you never have to be concerned abnout judging its behavior because it simply will not be able to execute.

 

An application that can't execute can't do any damage.

 

I hope you've enjoyed these postings on application whitelisting and I really hope that you've learned something from it. We've learned a tremendous amount from our customers and what's enabled them to make the transition to a whitelisting environment. Now it's your turn to ask yourself one more time: are you ready for enterprise application whitelisting?

1 Comments Click here to read/write comments

Are You Ready for Enterprise Application Whitelisting? Part 3

Posted by Brian Gladstein on Thu, Mar 20, 2008
  | Share on Twitter Twitter | Buzz This  Google Buzz | Submit to Digg digg it |  Share on LinkedIn LinkedIn 

I'm writing my third posting in a series called "Are You Ready for Enterprise Application Whitelisting?" The purpose of these posts as I've mentioned previously is to help IT people understand if their processes and organization are advanced and mature enough to be ready for implementing whitelisting - and basically only letting software run on corporate PCs that has been pre-authorized.

 

My previous posts covered a couple questions, including "Is your IT staff stretched too thin?" and "Do you need better auditing, reporting, and compliance?" Both of these questions are related to the needs of the organization and the services IT provides. But our next checkpoint asks about the maturity of the systems that IT uses to manage PCs. So here it is:

 

Question 3: Are adequate software delivery (SMS, WSUS) systems in place?

 

So why do we ask this question? Well the reason is because if you have implemented good, strong processes for delivering software easily and efficiently to desktops, you are pretty much at the point where the next logical step for control would be to whitelist the software on those PCs.

 

Think about it this way. Most company's IT processes have matured over the years along a relatively consistent pattern:

 

  1. Provisioning / Imaging: Make it easy to get a standard image of the operating system and core applications when a new PC is issued to an employee, without taking a lot of time.
  2. Deployment / Delivery: Get new applications or updates to applications out to all the users without having an army of IT people carry CDs to each workstation one by one.
  3. Patch Management: Every time a new vulnerability or exploit is announced, vendors rush to deliver patches. A smooth patch management process means you don't have to scramble to protect your PCs.


So once you have these three components, you have effectively achieved total control over pushing software out to your PCs. So what's next for you? What are you looking to achieve after control over "pushed software?"

 

The answer is control over "pulled software." Users will receive their provisioned PCs and use the apps that are pushed to them... but then they will get on the Internet and start downloading their own apps. And as powerful as your software deployment processes are, most organizations can not reach 100% coverage of the apps that their users need. So you have to rely on users being able to download apps for themselves so you don't have to send IT people to every user whenever they need something.

 

And now you've opened Pandora's box. Because you can't control what your users will install...

 

... unless you whitelist.

 

Because when you whitelist, you authorize your users to download certain apps, but they can't get whatever they want. This gives you control. 

0 Comments Click here to read/write comments

The Top 10 Most Vulnerable Applications for 2007

Posted by Brian Gladstein on Wed, Oct 24, 2007
  | Share on Twitter Twitter | Buzz This  Google Buzz | Submit to Digg digg it |  Share on LinkedIn LinkedIn 

We've just released our top 10 list of the most vulnerable applications for 2007. This is the second year we've put the list together, and it is focused on those applications that users tend to download. These apps are often very difficult for IT to see, let alone patch, and therefore represent unexpected and unquantified vulnerabilities in an enterprise IT environment.

 

To make it onto the list, the following criteria must be met. Each application:

 

  1. Must run on Microsoft Windows
  2. Must be well-known in the consumer space and frequently downloaded by individuals.
  3. Must not be classified as malicious by enterprise IT organizations or security vendors
  4. Must contain at least one critical vulnerability:
    • first reported in June 2006 or after,
    • registered in the U.S. National Institute of Standards and Technology’s (NIST) official vulnerability database at http://nvd.nist.gov, and
    • with a severity rating of high (between 7.0-10.0) on the Common Vulnerability Scoring System (CVSS).
  5. Relies on the end user, rather than a central administrator, to manually patch or upgrade the software to eliminate the vulnerability, if such a patch exists.

 

It is important to note that in most cases, the vendor or publisher of the applications on this list has already produced a patch for the particular vulnerability or vulnerabilities reported here. But at a company, there is usually no way that IT can ensure that the patch has been properly applied - that's requirement #5 on the list of criteria above.

 

Last year when we released this list, a lot of people commented on how we left off so much Microsoft software - some even going so far as to say that Microsoft sponsored this research! So let me be clear - this is entirely produced and financed by Bit9. The reason most Microsoft software doesn't make the list is because by now most companies have a pretty good process in place for identifying, patching, and fixing vulnerable Microsoft software. The same can not be said for apps like Firefox, iTunes, and other packages.

 

You can download the full list of vulnerable applications here which includes the specific versions, the vendors' solutions, the nature of the vulnerabilities, and references to the CVE numbers for the identified vulnerabilities. Also, you can learn what to do to help protect your company from vulnerable applications like these.

 

So without further ado, here are the apps on the list. Do you have a comment about it? Please submit!

 

  1. Yahoo! Messenger 8.1.0.239 and earlier
  2. Apple QuickTime 7.2
  3. Mozilla Firefox 2.0.0.6
  4. Microsoft Windows Live (MSN) Messenger 7.0, 8.0
  5. EMC VMware Player (and other products) 2.0, 1.0.4
  6. Apple iTunes 7.3.2
  7. Intuit QuickBooks Online Edition 9 and earlier
  8. Sun Java Runtime 1.6.0_X
  9. Yahoo! Widgets 4.0.5 and previous
  10. Ask.com Toolbar 4.0.2.53 and previous

5 Comments Click here to read/write comments

All Posts

Subscribe by Email

Your email: