<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - patch-management</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/patch-management/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2015-06-01T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/patch-management/atom.xml</id>
    <entry xml:lang="en">
        <title>Taking Control of IT Operations through the Critical Security Controls</title>
        <published>2015-06-01T00:00:00+00:00</published>
        <updated>2015-06-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/taking-control-with-critical-security-controls-csooutlook/"/>
        <id>https://blog.itys.net/vol1/posts/taking-control-with-critical-security-controls-csooutlook/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/taking-control-with-critical-security-controls-csooutlook/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The CSO Outlook article Taking Control of IT Operations through the Critical
Security Controls by Matthew J. Harmon explains how embedding the first five of
the SANS&#x2F;CIS 20 Critical Security Controls into everyday IT processes can
transform security from a reactive cost center into a proactive, measurable
discipline.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;starting-easy&quot;&gt;Starting Easy&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon shows that many breaches start with unknown or low-priority
systems, devices and software not inventoried or patched. Controls 1 (Inventory
of Authorized and Unauthorized Devices) and 2 (Inventory of Authorized and
Unauthorized Software) create visibility by correlating DHCP, ARP, and DHCP
assignments for hardware and using WMIC, RPM&#x2F;APT, or SCCM to catalog installed
applications. This foundational inventory maps assets to owners, enables
application whitelisting, and allows organizations to detect unauthorized
additions before attackers can pivot.&lt;&#x2F;p&gt;
&lt;p&gt;Next, the article tackles Controls 3 through 5: secure configurations,
continuous vulnerability assessment and remediation, and malware defenses.
Harmon advocates applying vendor and CIS hardening guidelines via Group Policy
Objects or configuration-management tools (Puppet, Chef), enforcing a 48-hour
patch window for critical flaws through tiered testing and deployment, and
layering defenses beyond antivirus, such as host firewalls, DNS filtering (e.g.,
OpenDNS), and threat-intelligence driven proxies. He concludes by recommending a
gap assessment against the remaining controls and a phased implementation
roadmap to embed these practices into routine IT operations and gauge their
impact over time .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57174_2015-06-01_Taking_Control_with_Critical_Security_Controls-CSOOutlook.pdf&quot;&gt;CSO Outlook: Taking Control of IT Operations Through the Critical Secuity
Controls&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Java Exploits: Offense and Defense</title>
        <published>2012-10-24T00:00:00+00:00</published>
        <updated>2012-10-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/java-exploits/"/>
        <id>https://blog.itys.net/vol1/posts/java-exploits/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/java-exploits/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmons (ISC)2 Twin Cities Chapter presentation Java Exploits:
Offense and Defense, delivered on October 24, 2012, examines the pervasive risk
of client-side Java vulnerabilities and outlines why these flaws represent a
critical attack vector for organizations. Harmon, drawing on his two decades of
security experience, highlights how the Java sandbox can be bypassed via
reflection and code injectiondemonstrated by high-impact exploits documented by
researchers like Joshua Drake and Adam Gowdiakand underscores the urgency of
addressing these pervasive weaknesses.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;attacks&quot;&gt;Attacks&lt;&#x2F;h2&gt;
&lt;p&gt;The talk begins by quantifying the threat: in 2012 alone, 23 out of 50 Oracle
JRE vulnerabilities carried a CVSS score of 10, signaling complete system
compromise without authentication. Harmon dissects sample exploit code that
disables the Java SecurityManager by injecting an AllPermission-granted
ProtectionDomain, illustrating how easily an attacker can escalate privileges.
He reviews major sandbox escapes and stresses that patch cycles alone cannot
keep pace with adversaries who weaponize newly discovered flaws .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;defense&quot;&gt;Defense&lt;&#x2F;h2&gt;
&lt;p&gt;To counter these risks, Harmon presents a two-pronged defense strategy. On the
technical side, he advocates strict whitelisting of Java applets via Group
Policy, Click-to-Run settings in browsers to prevent drive-by code execution,
and deployment of inline or local sandboxessuch as Invinceas VM-based isolation
or FireEye appliancesto contain untrusted code. Complementing this, he urges
policy-driven measures: eliminate Java where it isnt business-critical, enforce
inventory and configuration controls per the SANS Critical Security Controls
(especially Controls 15), and integrate Java risk assessments into broader
security governance. By combining these controls, organizations can
substantially reduce their Java attack surface and stay ahead of emerging
exploit techniques .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56224_2012-10-24_JavaExploitsOffenseAndDefense-ISC2TC.pdf&quot;&gt;Java Exploits Offense and
Defense&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
