Dr. Dobb's is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


Channels ▼
RSS

Top 10 Reasons Security Products Don't Work


9. Users fail to update the product as it evolves

Only one thing is constant about security products: Change. As exploits evolve and new technologies become available, your vendors will make changes in their products, and you must change yours as well. If you don't, you could leave yourself open to attack.

"One of our biggest frustrations in the enterprise anti-virus business is that a lot of companies don't keep their AV software up to date," says Symantec's Foster. "The threat space is constantly changing, and we're constantly changing our product to keep up. But if you don't do the updates, you're not going to get the benefit of those changes."

Roeckl echoes that frustration. "We develop a solution, and then nobody [at the customer site] does the update," he says. Fortinet is addressing this problem for some customers with a new option called FortiGuard, which distributes updates and configuration changes automatically via the company's distribution network.

"That works for a lot of smaller companies, though large companies often want to pre-stage a deployment and test it before they do an update," Roeckl says.

The vendors were careful to distinguish "updates" -- which are typically revisions designed to help the product stop a new exploit -- from "upgrades" or "new releases," in which the vendor adds new functionality to the product. Updates should be done frequently and as quickly as possible without replacing the existing software or appliance; upgrades require a wholesale replacement of older products, and often don't happen until long after a new release becomes available.

"I'm delivering a new release of our anti-virus products every 12 months, but I recognize that a lot of users can't keep up with me," says Symantec's Foster. Anderson says many enterprises can take as long as one or two years to do an upgrade, even if the new software is free under a maintenance agreement.

Whether you're doing an update or an upgrade, it's a good idea to familiarize yourself with a new piece of software before you begin to use it, Roeckl observes. "Occasionally, we'll find a small feature in a product that people really like, so we'll raise its status in the GUI," he says. "At that point, a lot of users will complain because they can't find it in the new release." In making the product more useable, a vendor may change the user interface and cause a temporary panic, he explains. "It's a little like getting Vista, and finding out that it looks a whole lot more like MacOS," he says. "It's a better interface, but it can be confusing to the user at first."

Bottom line: When a vendor updates one of your security products, you should deploy the update as swiftly as possible. Failure to do an update can leave your systems vulnerable to attack.


Related Reading


More Insights






Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dr. Dobb's encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dr. Dobb's moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing or spam. Dr. Dobb's further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.