Slowing or stopping the advance
of the Conficker worm is a tremendous patch management and configuration
management challenge. The problem is that organizations have a hard time
knowing what patches are really installed and how systems are actually
configured. Small organizations or individuals may be able to
retain control, but most organizations are in a constant state of flux:
new physical computers join the network, configuration settings change,
and new software applications are added. The problem has gotten even
worse with the increased emphasis on virtualization. Tools made by
companies like Microsoft and Symantec require Agents – software for managing
patches and configuration settings -- be installed on the systems they are
trying to protect. If companies can’t get an agent installed on a
machine, they can’t find it, and therefore can’t fix it! The only
realistic approach is to have patch management and configuration management
software that can work without the need to install agents and has the ability
to assess and fix both physical and virtual machines. The
Conficker.C variant is particularly nasty in that it targets security software
in an effort to disable or render it ineffective. The worm actually
blocks the Microsoft patch management agent. At Shavlik we focus on
making technology that is simple and does not require software (agents) on the
target computer. We have always done this, and at a time like this, our
product is uniquely qualified to combat the threat of Conficker.C!
We can talk about our free
assessment for the missing patch and misconfigurations.
More details at: