Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

BlueLane provides patch management safety net

PatchPoint appliance protects servers by patching applications on the network wire

By Roger A. Grimes
November 30, 2006
 

Last week a client of mine applied the latest OS patches to its main Microsoft Windows Server 2003 server. It rebooted and kaboom! No workstations could connect to the server. After uninstalling all the patches, it began communicating again.

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

Free IT resource

Attend the SOA Executive Forum: Breaking SOA Bottlenecks SOAExecForum.com/may2007

Sponsored by InfoWorld

TEST CENTER DAILY BLOG

Track the latest product reviews and news from the InfoWorld Test Center.




BlueLane PatchPoint G/450

BlueLane Technologies, bluelane.com

Excellent  8.7
criteria score weight
Effectiveness 9 30%
Ease-of-use 9 20%
Management 9 20%
Reporting 7 10%
Setup 9 10%
Value 8 10%

Cost:
Appliances and first year service start at $9,995.

Platforms:
Server versions of Microsoft Windows (Windows NT 4.0 and above), IIS, Microsoft SQL, Oracle, Apache, Red Hat Linux, Sun Solaris, and various Unix applications

Bottom Line:
Blue Lane PatchPoint patch proxy appliance is a laudable addition to the IPS field. PatchPoint excels at protecting unpatched Windows, Linux, and Unix servers against many publicly known exploits for popular applications by analyzing network packets and removing harmful bits. However, PatchPoint does not patch client-side applications such as Internet browsers or e-mail clients.

About our Reviews and Scoring Methodology

I have many clients afraid to apply Microsoft patches to their servers because of similar experiences. Oracle, and many other major vendors, have had to re-release patches to fix vendor-induced bugs. So should you apply the patches quickly to beat the hackers to the punch, or risk waiting a few weeks to let the vendor work out all the bugs?

Enter Blue Lane Technologies’ PatchPoint appliances. The PatchPoint family is an inline patching proxy. Essentially, administrators can forgo or delay installing OS and common application patches on Windows, Linux, and Solaris servers; instead, patches are “applied” on the network packet stream. Each incoming network packet headed for a protected server is statefully inspected for exploit code. The incoming packet can then be “patched” to make the exploit benign, log it and raise an alert, or drop the involved session.

It’s a unique level of flexibility not found in most IPSes. Although Blue Lane doesn’t recommend putting off a vendor patch forever, it does give the administrator a more flexible deployment schedule. Think of it as Tivo for patches.

Protect and prevent
I reviewed the PatchPoint G/450 (Release 2.7-G256 code) gateway, a 2U box with four Gigabit 10/100/1000 Ethernet ports spread equally over two segments, plus redundant power supplies and fans. A separate, required PatchPoint M/10 management appliance manages anywhere from one to 100 PatchPoint G/450 gateways.

The PatchPoint gateway device sits inline between the untrusted network domains and the servers to be protected. Initial IP configuration is done using an out-of-band serial DB-9 session. Afterward, the PatchPoint gateway can be set to auto-discover all the server computers on a particular subnet. It discovered all the servers on my test network except one, a Microsoft ISA firewall server. This was because the ISA didn’t respond to the auto-discovery ICMP and TCP echo tests. Administrators will have to add non-responding servers manually, as they already have to do with most auto-discovery tools.

After it locates the servers, PatchPoint uses active fingerprinting and passive network traffic listening to find server services that need patching. I was impressed with how many services it found and how well it fingerprinted the services, not to mention that the gateway located and correctly identified all the dynamic RPC ports. In a few cases, I had to manually help the gateway decide between various patch levels, but overall it did a great job by itself.

One other caveat -- the gateway looks at the common default ports and many other lower numbered ports during auto-discovery. Services running on high non-default ports, such as RDP running on 43389, were not located automatically and would have to be added manually.

After the services are discovered and identified, the administrator can apply protection to all of them at once or pick and choose. The default action can be set to Apply Fix (make exploits benign), Log and Alarm, or Drop Sessions. PatchPoint comes with a handful or two of pre-canned, graphic chart-style reports, but more detailed data can be downloaded to Microsoft Excel or CSV file.


Continued
1 | 2 | Next Page » 



 


 
Roger A. Grimes is contributing editor of the InfoWorld Test Center.
 

TOP NEWS:


»  Update: HP in talks to buy EDS for up to $13 billion
Deal would strengthen HP's competitive position against IBM, but still would leave it about $10 billion short of IBM's global services revenue

»  Cisco's TelePresence gets personal
The high-definition virtual meeting system will be available at a less expensive entry price for midsized businesses later this year

»  Developers' role shifting from apps to platforms
Untrained workers are moving into app dev space, pushing career developers into the platform space, a Sun engineer noted at JavaOne

»  Phishers scamming IRS rebates
A new scheme sends a fraudulent IRS that directs users to a Web site that asks for their bank account information in order to direct deposit their stimulus checks

»  iPhone out of stock 'company wide,' say Apple sales reps
Outage of iPhones has fueled rumors that the next-generation 3G model will be released shortly

»  Update: Google steps into data portability dance with Friend Connect
Google launches a preview version of Friend Connect, a service designed to let Web publishers add social networking features to their sites




Virtualization: A Step by Step Approach to Success
Your virtual machines can be up and running in a matter of minutes. HP and Citrix have integrated XenServer with HP ProLiant servers and management tools, powered by hardware-assisted Intel Virtualization Technology to enable high- performance, cost-savings solutions for server consolidation and disaster recovery. Sponsor: HP

»  Click here to view this Webcast
  The Data Protection You've Been Looking For
Enterprise data is of supreme importance. If you can't find it quickly, it's worthless. If you lose it, it's a crisis. This IT Strategy Guide explores how to keep your data safe.

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS  IT EXEC-CONNECT   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist