Network Patching Is Not An Alternative To Third-Party Patching, Chris.
Thomas Ptacek | September 27th, 2006 | Filed Under: Defenses, Industry Punditry, Uncategorized
Chris Hoff writes (ostensibly) about third-party patching, employing a paeon to Bleu Lane so wrong headed that I’m left to wonder whether pod people have taken over his brain.
Bleu Lane, for those of you who don’t keep track of these things, sells something they call “inline patching”. The idea is, well, I’ll let their pictures explain it for you:
![[before]](http://www.bluelane.com/lib/img/ActiveFixExample1.png)
![[after]](http://www.bluelane.com/lib/img/ActiveFixExample2.png)
You see what they did there? The box takes in shellcode, and then, by “emulating the functionality of a patch”, spits out valid traffic. Wow. That’s amazing. Now, somebody please tell me why that’s any improvement over taking in shellcode, and then, by “emulating the functionality of an attack signature”, spitting out nothing?
Yes, the problem with Bleu Lane Patch Point is that it doesn’t seem to be anything more than a slick marketing story over conventional IPS. Even the message is derivative; ISS used it for RealSecure four years ago. But unless you fund a marketing team millions of dollars to lie by repeated assertion, nobody believes that this is the equivalent of patching.
But that rant is actually a digression from my actual problem with Hoff’s post. Because even if it worked, Bleu Lane has nothing to do with third-party patches.
The power of a third-party patch is that by preempting the vendor, vulnerabilities can be disclosed without waiting. Real third-party patches are inherently “zero-day” patches; what to do with a zero-day patch is a decision you’ll have to make days before an IPS engineer figures out what to do with it.
I’m willing to believe that Chris’ bacon has truly been preserved by a PatchPoint appliance (though I’ll point out that if he bought one two years ago, he apparently had a beta: PatchPoint launched in September ‘05). He’d be telling one of the first stories of someone getting actual protective value out of an IPS, but I’m willing to believe it. I’m also willing to believe that Chris’ interests are profoundly aligned with promoting network-based solutions to security problems, and that they tend to be aligned with promoting network vendors as well.
Am I wrong about PatchPoint? Let me know.


Add New Comment
Viewing 25 Comments
Thanks. Your comment is awaiting approval by a moderator.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Add New Comment
Trackbacks