Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


April 30, 2008

Is Vista Easier to Patch Than Linux or UNIX?

RSS
Subscribe to Windows IT Pro | See More Macintosh Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Recently Jeff Jones (strategy director in the Microsoft Security Technology Unit) released an updated "one year vulnerability report" regarding Windows Vista. The data in the report shows how Vista compares to Windows XP, Red Hat Enterprise Linux 4 Workstation, Ubuntu 6.06, and Mac OS X 10.4 in terms of vulnerabilities during each OS's first year in the marketplace.

Jones used a variety of criteria for the comparison, including limiting the applications that he analyzed for the sake of keeping the competing OSs in line with a typical Vista installation. For example, RedHat and Ubuntu ship with OpenOffice installed by default on desktop systems. Jones didn't consider vulnerabilities in OpenOffice as part of his analysis. Other omissions were made of tools such as the Gimp graphics program and the gcc compiler, depending on the OS.

When the results were tallied, Jones found that during Vista's first year, 36 vulnerabilities were fixed by 17 patches in 9 patch events. The events were regular due to Microsoft's scheduled monthly patch releases. XP on the other hand experienced 65 vulnerability fixes in 30 patches for a total of 26 events. Quite a difference, as should be the case at this point in Windows' evolution.

RedHat Enterprise Linux 4 Workstation experienced 360 vulnerability fixes in 125 patches in 64 patch events. Ubuntu 6.06 experienced 224 vulnerability fixes in 80 patches in 65 patch events. OS X 10.4 experienced 116 vulnerability fixes in 17 patches in 17 patch events.

The low number of patch events for Vista and OS X are due to Microsoft's and Apple's routine of issuing patches on relatively fixed schedules. RedHat and Ubuntu on the other hand publish security patches immediately after they become available. So there's a trade-off involved: The approach used by Microsoft and Apple reduces the amount of administrative overhead but leaves customers exposed to security risks longer than if patches were issued immediately upon creation.

Near the beginning of the report, Jones suggests how the data might be useful by posing two questions: "All other things being equal, is it easier to mediate risk on a system that has 10 vulnerabilities in a year or one that has 100 vulnerabilities in a year?" And, "Which has a more negative impact on your security team and risk management process - deploying 10 security updates per year or deploying 100 security updates per year?"

The answer to first question is rather obvious: Of course it's easier to handle risk on systems with fewer vulnerabilities, assuming that we're talking only about patching holes and nothing else. The second question is too narrow because it overlooks the fact that Windows is the most targeted OS on the planet. Maybe asking yourselves how that fact affects your security team and risk management process would be more realistic. That aside, some of us would rather have patches immediately even if that means installing patches 100 times throughout the year.

Another issue not taken into consideration when posing those questions is the issue of downtime. To give you a good idea of the ramifications of less-than-stellar patch installation processes, refer to my editorial of March 5, 2008, "Windows Server: The New King of Downtime" (URL below). You might recall that according to Yankee Group, Windows Server has the worst downtime record of any mainstream server OS. The downtime record is due almost entirely to patch management.

http://windowsitpro.com/article/articleid/98475/windows-server-the-new-king-of-downtime.html

When patching any version of Windows, a reboot is often required, and in many cases the OS must be made unavailable to help manage the patch process. By comparison, UNIX and Linux systems typically don't experience such extreme burdens. For example, I've loaded many security patches on Ubuntu desktops and servers, and so far I've never had to reboot the systems nor take them offline--even systems that run high-traffic Apache and MySQL servers. Nor have I ever experienced a patch that breaks system components or services. Maybe I'm just lucky, but I don't think so.

Last week I did a complete OS upgrade on some Ubuntu desktops. The upgrade required the installation of 1,234 new packages. The upgrade ran completely in the background and didn't interrupt system use during installation. The systems were down for a total of about 30 seconds due to a need to reboot because the upgrades were major--similar to upgrading Vista with SP1. As far as I can see Linux is far easier to upgrade or patch than Windows.

Although I don't think Jones's report is anything to give a lot of weight to, if you're interested in reading it you can download a copy in PDF format at Jones's blog at the first URL below. And, if you're interested to see how Windows is still the most targeted OS on the planet, get a copy of Microsoft's new Security Intelligence Report at the second URL below.

http://blogs.technet.com/security/archive/2008/01/23/download-windows-vista-one-year-vulnerability-report.aspx

http://www.microsoft.com/downloads/details.aspx?FamilyId=BCC879DB-9FE6-4331-B231-E274EA8FC804&displaylang=en

Microsoft has a long way to go to improve its patch management process. It needs to be more transparent, and patches need to be more thoroughly tested before they become available. If Microsoft could achieve that, then the company could ditch its monthly patch release schedule and make patches available immediately as in the past, but this time without putting a huge burden on administrators and end users. As things stand now, there's fear every Patch Tuesday that a patch is going to break systems. I bet that, like me, many of you never experience that fear with your Linux platforms.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

More fun TechEd 2005 Resources

Kevin points out some more TechEd resources ...

What service packs and fixes are available?

...


Security Whitepapers Protecting (You and) Your Data with Exchange Server 2007

Extended Validation SSL Certificates

Unauthorized applications: Taking back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Microsoft Exchange & Windows Connections event returns to Las Vegas Nov 10 - 13
Connections returns to Las Vegas for this exciting event where each attendee will receive SQL Server 2008 standard with 1 CAL. Co-located with Microsoft ASP.NET, SQL Server, and SharePoint Connections with over 250 in-depth sessions.

Free Online Event! Virtualization:Get the Facts!
Register now and attend this free, live in-depth online conference on November 13 and 20, 2008, produced by Windows IT Pro. All registrants are eligible to receive a complimentary one-year digital subscription to Windows IT Pro (a $49.95 value)!

Check Out Hyper-V Video on ITTV
Watch Karen Forster's interview on Hyper-V's performance on ITTV.net.

Ease Your Scripting Pains with the Flexibility of PowerShell!
Join MVP Paul Robichaux on December 11, 2008 at 11:00 AM EDT as he equips you with PowerShell basics in 3 introductory lessons, each followed by a live Q&A session—all on your own computer!

Latest Advancements in SSL Technology
There are a variety of different kinds of SSL to explore to ensure customer data is kept confidential and secure. In this paper, we will discuss some of these SSL advances to help you decide which would be best for your organization.

PASS Community Summit 2008 in Seattle on Nov 18-21
The don’t-miss event for Microsoft SQL Server Professionals. Register now and you’ll enjoy top-notch Microsoft and Community speakers and more.



Solving PST Management Problems
In this white paper, read about the top PST issues and how to administer local/network PST Files.

Get Protected -- Data Protection Manager 2007
Protect your virtualized environment with Data Protection Manager

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Maximize Your SharePoint Investment: Get Your Data Moving
Watch this web seminar now to learn how to maximize your SharePoint investment! Join us as we take a look at the complex business of securing, accessing and managing vast amounts of information in a global network and various ways to get your data moving.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing