Subscribe to Windows IT Pro
November 25, 2003 12:00 AM

Enterprise Patch Management for Windows

Find help for managing security patches
Windows IT Pro
InstantDoc ID #40710
Rating: (1)

Application Security
When installing a patch-management solution, the last thing you want is to introduce more security holes to your network. Because a patch manager has a wide reach across an enterprise, it must be secure.

Patch managers must obtain patches and patch information databases from a reliable source and must ensure that they're working with original, unmodified files. Most of the products had strong security features. BigFix Patch Manager uses a public key encryption system for which the company issues its own certificates. Although someone might be able to gain access to the application and view hotfix information, he or she can't take any action without knowing the certificate's credentials. HFNetChkPro uses extra caution by checking not only signatures on the XML files and downloaded patches but also on each of the application's executables.

One problem with agentless patch managers is that Windows doesn't encrypt much of the information queried from network hosts. To properly secure this type of traffic, you need to implement IP Security (IPSec) or some other encryption between the scanning server and network hosts.

Scalability
Scalability is a vital concern for some administrators. The products we tested differed widely in their ability to scale to different environments. When evaluating patch-management solutions, consider the following criteria:

  • How many end-user systems will you manage?
  • How many administrators will use the patch manager?
  • How many patch-manager consoles will you need?
  • How will you segment your network for patch management?
  • How much bandwidth do you have available?
  • How much time do you want to spend managing the patch manager?

Of all the products tested, BigFix Patch Manager was the most scalable, with PatchLink Update following close behind. BigFix designed Patch Manager with scalability in mind; each console can efficiently handle up to 15,000 clients. BigFix Patch Manager also uses relays to establish multiple patch distribution points across a network. Although the other solutions don't have fixed limits for the number of clients they can support, they're not well suited for handling more than 5000 clients per console; however, you can break up the network into segments and manage each segment with a separate console.

Reporting
BigFix Patch Manager, Service Pack Manager 2000, and SysUpdate had the most flexible and useful reporting options. Most of the others had some reporting features but had limitations on output format, features, or interactivity. BigFix Patch Manager provides a user-friendly Web-based reporting module filled with features such as filtering, custom fields, charting, interactive links, and exporting to Microsoft Excel. Service Pack Manager 2000's template-based reporting provides many of these same features without the Web interface. SysUpdate uses Crystal Decisions' Crystal Reports for its reporting engine, allowing for powerful reporting options if you have access to the Crystal Reports Designer. HFNetChkPro also provided powerful reporting capabilities with flexible report criteria and numerous export formats.

Although not all the products have advanced reporting features, they all provide an export feature so that you can use an external reporting mechanism. And many of the products allow ODBC access to their scan databases, providing further options for custom reporting.

Our lab tests didn't single out one overall winner; some products are simply better suited for certain environments. Consider your requirements for flexibility, accuracy, deployment, product coverage, security, scalability, and reporting and compare them with the feature comparison in Web Table 1. Patch management is an industry still in its infancy, and plenty of room for improvement exists, but we've come a long way from where we were just a few years ago. The number of patch-management solutions is growing, and each solution is growing in features and reliability. The hard part is finding the solution that's right for your environment.



Patch-Management Software Vendors
BigFix * 510652-6700 * http://www.bigfix.com

Ecora * 603-436-1616 * http://www.ecora.com

Gravity Storm Software * 858-792-0162
http://www.securitybastion.com

PatchLink * 480-970-1025 * http://www.patchlink.com

SecurityProfiling * 765-420-7227 * 888-645-3676
http://www.securityprofiling.com

Shavlik Technologies * 651-426-6624 * http://www.shavlik.com

St. Bernard Software * 858-676-2277 * http://www.stbernard.com


Related Content:

ARTICLE TOOLS

Comments
  • Anonymous User
    8 years ago
    Dec 15, 2004

    I work with patchlink, is a great tool. if you need to use in several computers the solution is change de computer name, and re install agent it...

  • Anonymous User
    8 years ago
    Oct 28, 2004

    This blows

  • Jimi Thompson
    8 years ago
    May 26, 2004

    1) SUS Blows!! All it does it give you your very own copy of http://v4.windowsupdate.microsoft.com/en/default.asp. If you're looking for something more than "Critical Updates" and "Recommended Updates" look somewhere else.

    2) Most products either have a prohibitive price tag or a prohibitive feature set. If someone wanted to cash in, they'd have a product with a good feature set, some purchasable add ons (like a good help desk system) and sell it for cheap.

  • Joe Crowe
    8 years ago
    May 11, 2004

    Just a quick response to Brandon Pack's comment....you can use Patchlink with Ghost....there are instructions on the Patchlink site.

  • anonynous
    8 years ago
    May 03, 2004

    the computer business is finished and is for losers nowadays...i'm going to law school

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.