On CHOW: Make your next sandwich perfect
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 1 of 30:
Next »
Windows Software Update Service and NAP
WSUS is what larger corporations, enterprises
and larger institutions use to ensure
stability of their platform.

It basically lets the administrator decide
which patches to apply when. He can also set up
policies so that different patches are applied
to different sets of computers, depending on
their location, organizational unit, roles etc.

The catch is that IF you decide to go with WSUS
you just HAVE to be diligent with the patches.
If you don't let them through, they will not
reach the clients.

A clever admin will of course set up non-
mission critical machines (usually the
majority) to patch automatically using
windowsupdate.

He should also set up group policies which
switches on the firewall on all client
machines. Firewalls switched on would have
protected even an unpatched machine against
conficker and a host of other threats.

Network Access Protection is available by
default since Vista. It basically lets the
administrator define policies for access to the
network.

If your client machine cannot prove that it
meets certain administrator-defined
requirements (i.e. fully patches, protected by
a certain antivirus suite, holder of a given
certificate etc.) no protected server/service
on the network will talk to it. Until it has
been fixed. By setting up a special
download/fix page even this can be automated.

The thing is, these definitions can be set up
to be largely automatic. There's really no
excuse for an admin NOT to ensure that machines
on the network are protected and fully patched.

At least this goes for an institution such as a
hospital. A school/educational environment is
more tricky because it inherently need to be
more open. It can still be done without too
much effort, though.

One way is to define the "public" nets (open
WiFi and wired ethernets) as "potentially
hostile". Only a few http based services (such
as an intranet etc) should be open for
unauthenticated clients.

Clients with a valid certificate (can be set to
download automatically to machines which are
part of the domain) could be allowed access to
the protected part of the network, subject to
NAP.

I agree that the threats will never go away.
Admins should be educated to take advantage of
the extra lines of defenses which are already
offered them as part of their Windows network.

And no, switching to another OS infrastructure
will not solve the problem. No other OS
infrastructure offers the same combination of
openness and lock-down mechanisms. Not without
paying through your nose.
Posted by: honeymonster   Posted on: 04/13/09 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Windows Software Update Service and NAP  honeymonster | 04/13/09
Pretty much means that  Lerianis | 04/13/09
At least someone's got some 'splaining to do (NT)  honeymonster | 04/13/09
How many machines total?  militant.agnostic | 04/13/09
What about your network?  InAction Man | 04/13/09
Yes, "blame the users"!  Zogg | 04/13/09
Stupid large institutions are not immune  qmlscycrajg | 04/13/09
From what I have seen  Lerianis | 04/13/09
Not so sure  honeymonster | 04/13/09
And why is that happening?  InAction Man | 04/13/09
Mostly in software  Mikael_z | 04/13/09
XP is 8 years old  zmud | 04/13/09
You don't see disasters happen this frequently  Mikael_z | 04/13/09
New Conficker "E" worm hits a Microsoft Nerve (again)  joe.smetona@... | 04/13/09
Even if...  bricar2 | 04/13/09
Based on what I've seen in the SRI report,  joe.smetona@... | 04/13/09
And robbers don't attack fort knox because of it's tiny market share  InAction Man | 04/13/09
NO. The problem lies in the fact that ...  mwagner@... | 04/14/09
Of course you say so  Mikael_z | 04/16/09
In one regard, you are correct ...  mwagner@... | 04/17/09
Good reasons...  Jeremy W | 04/13/09
I give up  reedmb@... | 04/13/09
Flat View  epcraig | 04/13/09
OT Flat view, was Large Institutions  dragonsclaw@... | 04/13/09
thanks  LiLac22281 | 04/13/09
RE: Even large institutions not immune to Conficker  apolicastro | 04/13/09
A non-event for RESPONSIBLE System Administrators...  Marty R. Milette | 04/14/09
No one is immune ...  mwagner@... | 04/14/09
not always the user's fault  charles.kronenwetter@... | 04/14/09
RE: Even large institutions not immune to Conficker  KeithNB | 04/20/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads