On GameSpot: TGS 2008: Tekken 6 heads to the Xbox 360
BNET Business Network:
BNET
TechRepublic
ZDNet

August 5th, 2008

Microsoft makes daring vulnerability sharing move

Posted by Ryan Naraine @ 5:40 am

Categories: Patch Watch, Zero-day attacks, Microsoft, Browsers, Vulnerability research, Responsible disclosure, Exploit code, Black Hat, Data theft, Pen testing, Arbitrary Code Execution, Anti Virus, Malware

Tags: Vulnerability, Security Company, Exploit Code, Microsoft Corp., Security, Ryan Naraine

Microsoft makes major Patch Tuesday changes, to share flaw data ahead of timeLAS VEGAS — Starting in October, Microsoft will start sharing details on software vulnerabilities with security vendors ahead of Patch Tuesday under a daring new program aimed at reducing the window of exposure to hacker attacks.

The new Microsoft Active Protections Program (MAPP), which will be formally announced at Black Hat USA 2008 here, will give anti-virus, intrusion prevention/detection and corporate network security vendors a headstart to add signatures and filters to protect against Microsoft software vulnerabilities.

The idea is to provide detection guidance ahead of time to help security vendors reproduce the vulnerabilities being patched and ship signatures and detection capabilities without false positives.

According to Mike Reavey, group manager in the MSRC (Microsoft Security Response Center), the new vulnerability sharing program was created to address the situation today where weaponized exploit code is being released to the public before Windows users can test and deploy the Patch Tuesday fixes.

[ SEE: Security is everyone’s domain ]

“This is not for the folks that build attack frameworks,” Reavey said, making it clear the MAPP program will not be available for penetration testing firms like Core Security and Immunity Inc., two companies in the business of reverse-engineering patches to create exploits for IDS/IPS and corporate customers.

“The amount of time between the release of a patch and the release of the exploit code [for that patch] continues to shorten and customers have been asking for information to react to this,” Reavey explained.   With MAPP, which launches officially in mid-October, security vendors will have signatures and filters ready to roll alongside the patches, potentially negating any exploit code release.

“We’re limiting that window of danger,” he added.   Microsoft is not saying exactly when the flaw data will be shared but a source tells me security vendors will get at least a 24-hour headstart.

[ SEE: Skeletons in Microsoft’s Patch Day closet ]

The move is not without major risk.   As everyone knows, vulnerability data is big business and the specter of a rogue employee with access to what amounts to zero-day vulnerabilities is a scary thought.  What happens if the information flowing through MAPP is being siphoned off and sold to malicious attackers?

Reavey acknowledges the risk and insists Microsoft will tightly lock down access to the program and implement measures to identify potential leaks.  Participants in the program must sign NDAs and have a significant enough customer base for protection-oriented software.

[ SEE: Punditry: Will Microsoft buy flaws? ]

Some criteria for participants in MAPP include:

  • Members must offer commercial protection features to Microsoft customers against network- or host-based attacks.
  • Members must provide protection features to a large number of customers.
  • Members may not sell attack-oriented tools.
  • Protection features provided by members must detect, deter or defer attacks.

Confirmed participants in the new program include IBM Corp., Juniper Networks and 3Com TippingPoint.  Correction: I’m not yet aware of any participants.  Apologies.

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the world. See his full profile and disclosure of his industry affiliations.

Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

  • Talkback
  • Most Recent of 7 Talkback(s)
And Apple?
Marketing pulls Apple's security engineers from the same
conference at the last minute. (Read the rest)
Posted by: Ed Lin Posted on: 08/06/08 You are currently: Logged In | Log out
have to say it's good Narr vi   | 08/05/08
I Agree. Good Move, finally. dunn@...   | 08/05/08
I'm not sure daring is the word... TtfnJohn   | 08/05/08
"Daring"? Resuna   | 08/05/08
Oh god not again tonymcs@...   | 08/05/08
Oh god, not "Oh god not again" again bmerc   | 08/06/08
And Apple? Ed Lin   | 08/06/08

What do you think?

No Trackbacks Yet

The URI to TrackBack this entry is:
http://blogs.zdnet.com/security/wp-trackback.php?p=1646

advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

advertisement
Click Here