HZFQ.COM
welcome to my space
X
Writing | Self Help | Travel | Wines and Spirits | Plastic Surgeries | Advertising | Forums | Banking | Related articles
Welcome to:hzfq.com
Search:  
 HOME   Task Force: Patches Must be Small, Easy to Install

Task Force: Patches Must be Small, Easy to Install

Published by: wktd 2008-12-01

A high-powered cybersecurity task force says software vendors must adopt patch management principles to ensure security patches are well-tested, small, localized, reversible and easy to install.

US experts outline security initiative - Infomatics::
A US task force of security experts, academics and business and government officials has released small, localised, reversible and easy to install.
http://www.infomaticsonline.co.uk/vnunet/news/2124698/experts-outline-security-initiative
HOME
ps3:mediacenter [psDevWiki]::
small base install (few installed packages); small memory footprint; can be optimized (recompiling is very easy); BUT: emerge is python and very slow :(
http://wiki.ps2dev.org/ps3:mediacenter
HOME

The National Cyber Security Partnership (NCSP), a public-private task force that includes participation from the Business Software Alliance (BSA), issued its recommendations in a 123-page report (PDF file) aimed at improving security across the software development lifecycle.

The NCSP made four key recommendations in its report, calling for an improvement in the education of software developers, the development of best practices to make sure security is at the core of the software design process, the adoption of guiding principles for patch management and the creation of an "incentives framework" for policymakers and developers.

The task force, which is co-chaired by Microsoft chief security strategist Scott Charney, proposed the creation of a new initiative to put security at the heart of software development programs at the university level. It also called for a Software Security Certification Accreditation Program.

Desktop Security Best Practices::
These are discovered frequently; therefore patches must be installed on a For HP/UX systems, download and install the patches on their web site at
http://itsecurity.olemiss.edu/BestPractices.htm
HOME

"Security is a serious problem and, if present trends continue, could be much worse in the future. No simple silver bullets will solve the software security problem," the group said. "As a long-term multifaceted problem, it requires multiple solutions and the application of resources throughout the lifecycle."

The report recommends that four sub-groups be created to focus on tightening Internet security in the face of a barrage of overt attacks by malicious hackers targeting software flaws. Initially, the group's Education sub-group insisted that security should be a key subject area in software development programs in schools.

Tools::
You may put big force on your tire levers, and you do not want to accidentally . Therefore the coated area must be bigger than the patch, and it must be
http://www.easystreetrecumbents.com/stuff/tools.html
HOME
A Patch for Enhanced OCaml Toplevel::
toplevel directory, as well as very small adjustment to . . package by yourself, thanks to the excellent work of Debian OCaml Maintainers Task Force.
http://www.pps.jussieu.fr/~li/software/enhtop/README
HOME

In the long term, the NCSP's "Patching" sub-group defined steps to help make that the patching process simple, easy, and reliable. The group called for the adoption of a "top-ten" list of best practices to ensure vulnerability patches are properly tested and simple to install.

"Patches would also not require reboots, use consistent registration methods, include no new features, provide a consistent user experience, and support diverse deployment methods," the group said.The task force calls for smaller, simplified patches comes on the heels on a concession from Microsoft that narrowband customers were having problems downloading and installing critical software fixes.

Earlier this year, Microsoft security program manager Christopher Budd told internetnews.com a removal tool for the destructive Blaster worm has to be stripped down to keep the file size small to reach dial-up users.

He said the file size and complicated nature of security patches are a "definite hurdle" the company faced in its attempts coax users with a dial-up Internet connection to wait through the download and then install the software fix.

"It is an intractable engineering problem. The smaller the patch, the less of a hurdle it will be to reach narrowband customers. That's the most effective thing we can focus on. I think we can reduce patch sizes and get it to an acceptable level but, it will always be a problem because of the way patches are designed," Budd said.




Mandrakesoft Is Out of Court, But Is It Out of Trouble?
Study: Virus Attacks Up But Infections Hold Steady

You are looking at:hzfq.com's Task Force: Patches Must be Small, Easy to Install, click hzfq.com to home
#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about Task Force: Patches Must be Small, Easy to Install , Please add it free.
 Homepage | Add to favorites | Contact us | Exchange links | LOGIN | Site map | 
Copyright© 2008 hzfq.com        Site made:CFZ