Top Banner
36

Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Dec 24, 2015

Download

Documents

Dwight Fields
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.
Page 2: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Managing Third Party Updates with System Center 2012 Configuration Manager SP1 Kent Agerlund & Lawrence Garvin• @Agerlund• @LawrenceGarvin

UD-B326

Page 3: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Who are weKent AgerlundChief System Management ArchitectCoretech A/S, Denmark Microsoft MVP: Configuration Manager Microsoft Certified Trainer, MCITP Enterprise Administrator

Lawrence GarvinHead GeekSolarwindsMicrosoft MVP: WSUSMicrosoft Certified IT Professional (MCITP)

Page 4: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Agenda• Why worry about 3rd party updates• What are your options

• SCUP 2011 (System Center Updates Publisher)• Install and configure, • Publish, import catalogs • Author, create custom updates

• Solarwinds• Integration with Configuration Manager 2012

• Secunia• Integration with Configuration Manager 2012

Page 5: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

What is patch management

PDPatch Deployment

PC

Patch Creation

+

Vulnerability Scanning

VS +VI

Vulnerability Intelligence

+ PM=

Page 6: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Microsoft Programs

14%Third Party Programs

86%

Why worry about 3rd party

Business

View

Criminals

ViewWhat

criminals attack

Business criticalprograms

Programs you know about

Programs you don’t know about

What do you patch

today

Vendors

Page 7: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

The numbers speaks for themselves – TOP 50 apps

Cybercriminals know:

patch available≠

patch installed

Vulnerabilitiesin 2012 TOP 50 Apps

1137

421 in 2009229 in 2007

Page 8: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

0 10 20 30 40 50 600%

20%

40%

60%

80%

100%

Percentage of risk remediated by patching N programs

Number of programs patched

Perc

enta

ge o

f ri

sk r

em

edia

ted

Patching N of 200 programs

80% risk reduction achieved by either patching the 12 most critical programs, or by patching the 37 most prevalent programs

12 37

Strategy 2: By CriticalityRisk remediated by patching the N most critical programs

Strategy 1: StaticRisk remediated by patching the N most prevalent programs

Where to begin

Page 9: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Are we doomed?

Page 10: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

SCUP 2011

Page 11: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

SCUP 2011

• What is SCUP• Authoring tool• Publishing tool

• 3rd Party Updates with SCUP• Same experience for all updates in ConfigMgr• Enables authoring of third party / line of business updates• Enables importing catalogs from outside sources (ISVs and OEMs)• Supports EXE, MSI and MSP based updates

Page 12: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

SCUP Requirements

• Supported Operating Systems: Windows Vista and later, Windows Server 2008 and later

• Windows Server Update Services (WSUS) 3.0 SP2• Trusted Signing Certificate

• Trusted root and trusted publisher store on all computers

• Support Configuration Manager 2007 SP2 & 2012• Single user application

Page 13: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

SCUP Process Flow

Author customSCUP catalog WSUS Server

Catalogs downloaded from web

ConfigMgr ServerSCUP Console

Publish Updates Sync Updates

ConfigMgr Clients

Scan Updates Deploy Updates

Author Updates

Import Updates

Page 14: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

The signing certificate

• Used by SCUP to sign updates • Trusted Publishers• Trusted Root

• Configure WSUS GPO• Allow self signed certificates

• Create the self-signed certificate with SCUP• External certificate - http://

blogs.msdn.com/b/steverac/archive/2011/09/18/using-system-center-update-publisher-2007-with-verisign-certificates.aspx

• KB2720211 & KB2661254

Page 15: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Available Catalogs• Free catalogs

• Adobe• Reader and Flash

• Dell• Client and Server updates

• Hewlett-Packard• Client and Server updates

• Fujitsu• ConfigMgr Cumulative updates

• $$ catalogs• Vcenter Protect from VMWARE• PatchMyPC

Page 16: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Installing SCUP

DEMO

Page 17: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Author updates

• Applicable rules• Supersedence• Templates• Installable rules

Page 18: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Author updates

DEMO

Page 19: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Secunia

Page 20: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Secunia

• Products• CSI – Corporate edition• SSB – Small Business edition• PSI – Consumer and free

• Cloud Based solution• Database contains vulnerabilities in software products

since 2003• 40k+ programs, applications and plug-ins from

thousands of software vendors• Automated patch repackaging• Fully integrated with 2012

Page 21: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Secunia Infrastructure

• Installation• Database Cloud VS Standalone• Administrator Console• Integration with Configuration Manager

• Requirements• https://*.secunia.com added to trusted zone in IE• Internet connection SSL 443/TCP to https://*.secunia.com/• WSUS Signing Certificate• WSUS GPO

Page 22: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Vulnerability Scanning• Process

• Collect metadata from *.exe, *.dll and *.ocx• Match against raw metadata against Secunia File Signatures• Compare software against Advisory & Vulnerability Database

• Metadata gathering• Locally installed agent• Agent running from a ConfigMgr package• ConfigMgr Software Inventory• Network scan

• How Often• Configurable

• Support for “Road Warriors”

Page 23: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Reporting

• Integrated with Configuration Manager• Custom Dashboard• Custom reports• E-Mail subscriptions

Page 24: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Deploying patches

• Custom created Secunia packages• Silent installations• Can detect running applications like JAVA

• Script support• PowerShell• VB• Java

• Updates are injected into WSUS

Page 25: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Secunia

DEMO

Page 26: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Solarwinds

• Product: Patch Manager• Database/Catalog info

• Created & tested by SolarWinds• Published to a web-based catalog• Automatically synchronized daily to Patch Manager server

• Packages • Contains all major desktop applications and browsers in use (e.g. Reader, Flash, Java, Firefox,

Chrome, iTunes, Quicktime, Skype, and others)• Provides toolset for customizing provided packages or building packages from scratch

• Fully integrated with ConfigMgr 2007 and 2012• Co-exists as snap-in with ConfigMgr 2007 when ConfigMgr2007 is run in a CLRv4 MMC• Fully integrated with the ConfigMgr 2012 console on the Software Library page

Page 27: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Solarwinds Infrastructure

• Install• Installs as a separate server.• Can be installed on Site Server or Software Update Point.

• Scanning Clients• All compliance scanning is performed by the Configuration Manager agent.

• Deployment• Deployment is handled through standard Configuration Manager deployment techniques• Patch Manager also provides optional deployment tools that can be used on-demand or as

scheduled events to deploy Third Party updates directly from the SUP

Page 28: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Vulnerability and Compliance Reporting

• Dashboard*

• Web-based read-only status

• Custom reports*

• Dozens of pre-defined compliance reports• All customizable

• E-Mail subscriptions*

* Requires WUAgent reporting of events to SUP.

Page 29: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Patching

• How• Configuration Manager Deployment Packages• Update Management Wizard (can deploy Third-Party updates from the SUP)

Page 30: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Solarwinds

DEMO

Page 31: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

The annoyance of….. Automatic Upgrade notifications

Adobe Flash

JAVA

Adobe Reader Apple Itunes

Firefox

Google Chrome

Page 32: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Annoyance of…..

DEMO

Page 33: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Links and Questions• Connect with Kent Agerlund & Lawrence Garvin

• Mail: [email protected] / [email protected]• Blog: http://blog.coretech.dk/author/kea / http://www.patchzone.org and http://www.thwack.com

• SCUP• Complete SCUP 2012 guide – http://blog.coretech.dk/kea/the-complete-scup-2011-installation-and-

configuration-guide/• SCUP videos - http://technet.microsoft.com/en-us/video/ff832960.aspx?category=Jason%20Lewis • PatchMyPC - http://patchmypc.net/• Vcenter Protect -

http://www.vmware.com/products/datacenter-virtualization/vcenter-protect-update-catalog/faqs.html• Adobe catalog - http://www.adobe.com/devnet-docs/acrobatetk/tools/AdminGuide/sccm.html

• Secunia• CSI - http://secunia.com/vulnerability_scanning/

• Solarwinds• Patch Manager - http://www.solarwinds.com/patch-manager.aspx

Page 34: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Evaluation

Complete your session evaluations today and enter to win prizes daily. Provide your feedback at a CommNet kiosk or log on at www.2013mms.com.Upon submission you will receive instant notification if you have won a prize. Prize pickup is at the Information Desk located in Attendee Services in the Mandalay Bay Foyer. Entry details can be found on the MMS website.

We want to hear from you!

Page 35: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

Resources

http://channel9.msdn.com/Events

Access MMS Online to view session recordings after the event.

Page 36: Patch Deployment Patch Creation Vulnerability Scanning Vulnerability Intelligence.

© 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.