RE: Handling new vulnerabilities like WebDav - SUMMARY

Harlan Carvey <[email protected]> Tue, 25 Mar 2003 13:15:50 -0800 (PST)
Newsgroups gmane.comp.security.incident-handling
Message-ID <[email protected]>
Robert,

> Minus the vendor plugs, here is a summary of the
> information I received on this thread in no
> particular order:

Thanks for providing a summary.
 
> 1.  Maintain an accurate inventory of your assets to
> include, OS, platform, applications, patch levels,
> services etc..  This can then be used to quickly
> identify your risk in relation to a new
> vulnerability.  As mentioned by several folks, this
> is extremely difficult and time consuming.

I work in an all-MS shop, and we've opted to go with
RippleTech's PatchWorks for patch management.  It's
extremely helpful in not only rolling the patches out,
but also keeping track of what's installed where.
 
> 2.  Use a preventative IDS solution to prevent the
> attack and then patch at your leisure.

"preventative IDS" is almost a contradiction in terms.
 Something that detects does not necessarily protect. 
As far as prevention, or "intrusion prevention" goes,
there are a number of ways to go about it, ranging
from system hardening to installing third party
products such as Okena's suite of products.  Other
products, such as Nokia + ISS RealSecure, bill or
market themselves as "intrusion prevention", but they
really aren't.

> 3.  Run an immediate scan of your environment to
> determine your risk.  Then patch, or implement
> mitigating controls based on the results.  Possibly
> use your ticketing system to create accountability,
> or send emails to those accountable.

This is pretty high-level, but completely accurate. 
"Scan", "determine your risk", and "mitigating
controls" are all very general terms that rely on a
lot of political and monetary factors within each
organization.

HTH,

Harlan




__________________________________________________
Do you Yahoo!?
Yahoo! Platinum - Watch CBS' NCAA March Madness, live on your desktop!
http://platinum.yahoo.com