1
1

00:00:00,120  -->  00:00:02,480
<v ->Patch management, in this lesson,</v>
2

2

00:00:02,480  -->  00:00:04,430
we're going to discuss a network hardening technique
3

3

00:00:04,430  -->  00:00:06,140
known as patch management.
4

4

00:00:06,140  -->  00:00:08,500
So what exactly is patch management?
5

5

00:00:08,500  -->  00:00:11,160
Well, patch management is the planning, testing,
6

6

00:00:11,160  -->  00:00:13,920
implementing, and auditing of software patches.
7

7

00:00:13,920  -->  00:00:16,610
Patch management is critical to providing the security
8

8

00:00:16,610  -->  00:00:18,830
and increasing uptime inside your network,
9

9

00:00:18,830  -->  00:00:21,200
as well as ensuring compliance and improving features
10

10

00:00:21,200  -->  00:00:24,290
in your network devices, your servers and your clients.
11

11

00:00:24,290  -->  00:00:26,530
Now patch management is going to increase the security
12

12

00:00:26,530  -->  00:00:28,870
of your network by fixing known vulnerabilities
13

13

00:00:28,870  -->  00:00:30,500
inside of your network devices,
14

14

00:00:30,500  -->  00:00:32,160
things like your servers, your clients,
15

15

00:00:32,160  -->  00:00:33,940
and your routers and switches.
16

16

00:00:33,940  -->  00:00:35,930
Now, in terms of our servers and clients,
17

17

00:00:35,930  -->  00:00:37,710
patch management is going to be conducted by installing
18

18

00:00:37,710  -->  00:00:39,740
software and operating system patches
19

19

00:00:39,740  -->  00:00:42,560
in order to fix bugs in the system software.
20

20

00:00:42,560  -->  00:00:44,520
Patch management can also increase the uptime
21

21

00:00:44,520  -->  00:00:46,900
of your systems, by ensuring your devices and software
22

22

00:00:46,900  -->  00:00:49,050
are up to date, and they don't suffer
23

23

00:00:49,050  -->  00:00:51,190
from resource exhaustion or crashes
24

24

00:00:51,190  -->  00:00:53,390
due to vulnerabilities within their code.
25

25

00:00:53,390  -->  00:00:55,130
Patch management is also used to support
26

26

00:00:55,130  -->  00:00:56,520
your compliance efforts.
27

27

00:00:56,520  -->  00:00:58,020
One of the biggest things is looked at
28

28

00:00:58,020  -->  00:00:59,390
within a compliance assessment,
29

29

00:00:59,390  -->  00:01:01,120
is how well your patch management program
30

30

00:01:01,120  -->  00:01:03,340
is being run and being conducted?
31

31

00:01:03,340  -->  00:01:05,350
This way you can ensure it's effective
32

32

00:01:05,350  -->  00:01:07,140
and making sure your systems are up to date
33

33

00:01:07,140  -->  00:01:09,420
and patch against all known vulnerabilities,
34

34

00:01:09,420  -->  00:01:12,480
such as CVEs or common vulnerabilities and exposures
35

35

00:01:12,480  -->  00:01:14,810
that have patches associated with those.
36

36

00:01:14,810  -->  00:01:17,130
Now patch management is also going to be used to provide
37

37

00:01:17,130  -->  00:01:18,540
improvements and upgrades to your
38

38

00:01:18,540  -->  00:01:20,270
existing feature set as well.
39

39

00:01:20,270  -->  00:01:23,230
Many of your patches don't just fix things or existing
40

40

00:01:23,230  -->  00:01:26,340
problems inside of them, but they can also add other things
41

41

00:01:26,340  -->  00:01:29,630
like features and functionality when you do those upgrades.
42

42

00:01:29,630  -->  00:01:31,240
By ensuring that you're running the latest version
43

43

00:01:31,240  -->  00:01:33,350
of the software and that it's fully patched,
44

44

00:01:33,350  -->  00:01:35,170
you can ensure you have the best feature set
45

45

00:01:35,170  -->  00:01:37,050
with the highest security available.
46

46

00:01:37,050  -->  00:01:39,440
Now, as you can imagine, there are a lot of different
47

47

00:01:39,440  -->  00:01:41,720
patches out there, because each manufacturer
48

48

00:01:41,720  -->  00:01:43,350
is going to create their own patches
49

49

00:01:43,350  -->  00:01:46,140
for their specific applications and software.
50

50

00:01:46,140  -->  00:01:48,860
Part of your job inside of the patch management process
51

51

00:01:48,860  -->  00:01:51,380
is keeping track of all the various updates and ensuring
52

52

00:01:51,380  -->  00:01:52,440
they're getting installed properly
53

53

00:01:52,440  -->  00:01:54,300
throughout all of your network devices.
54

54

00:01:54,300  -->  00:01:56,920
This includes your switches, your routers, your firewalls,
55

55

00:01:56,920  -->  00:01:58,960
and your servers and clients.
56

56

00:01:58,960  -->  00:02:01,070
Patch management is not just concerned with ensuring
57

57

00:02:01,070  -->  00:02:02,580
that a patch patches installed though,
58

58

00:02:02,580  -->  00:02:05,310
it's also important to ensure it doesn't create new problems
59

59

00:02:05,310  -->  00:02:07,470
for you when you do that installation.
60

60

00:02:07,470  -->  00:02:10,330
After all patches themselves can have bugs in them too,
61

61

00:02:10,330  -->  00:02:12,290
just like any other software can.
62

62

00:02:12,290  -->  00:02:14,730
Therefore it's really important for you to effectively
63

63

00:02:14,730  -->  00:02:18,070
conduct patch management by following four critical steps.
64

64

00:02:18,070  -->  00:02:21,220
First, planning, second testing,
65

65

00:02:21,220  -->  00:02:24,230
third implementing, and forth auditing.
66

66

00:02:24,230  -->  00:02:25,900
Step one is planning.
67

67

00:02:25,900  -->  00:02:27,736
Planning consists of creating policies, procedures,
68

68

00:02:27,736  -->  00:02:31,110
and systems to track the availability of patches and updates
69

69

00:02:31,110  -->  00:02:33,700
and having a method to verify that they're compatible
70

70

00:02:33,700  -->  00:02:35,130
with your systems.
71

71

00:02:35,130  -->  00:02:37,400
Planning is also used to determine how you're going to test
72

72

00:02:37,400  -->  00:02:39,200
and deploy each of those patches.
73

73

00:02:39,200  -->  00:02:41,490
A good patch management tool can tell you whether or not
74

74

00:02:41,490  -->  00:02:42,820
the patches have been deployed,
75

75

00:02:42,820  -->  00:02:44,800
installed and verified functionally,
76

76

00:02:44,800  -->  00:02:46,560
on a given system or client.
77

77

00:02:46,560  -->  00:02:48,950
For example, in large enterprise networks,
78

78

00:02:48,950  -->  00:02:49,783
you may use
79

79

00:02:49,783  -->  00:02:51,980
the Microsoft System Center Configuration Manager
80

80

00:02:51,980  -->  00:02:55,370
known as SCCM, or you can buy a third party tool
81

81

00:02:55,370  -->  00:02:57,130
to conduct your patch management.
82

82

00:02:57,130  -->  00:03:00,250
Step two, testing, when conducting patch management,
83

83

00:03:00,250  -->  00:03:02,720
it's really important to test any patch you receive
84

84

00:03:02,720  -->  00:03:05,380
from your manufacturer before you automate its deployment
85

85

00:03:05,380  -->  00:03:06,930
throughout your entire network.
86

86

00:03:06,930  -->  00:03:10,390
As I said before, a patch is designed to solve one problem,
87

87

00:03:10,390  -->  00:03:12,750
but it can also create new ones for you
88

88

00:03:12,750  -->  00:03:14,080
if you're not careful.
89

89

00:03:14,080  -->  00:03:16,290
Within your organization, you need to ensure
90

90

00:03:16,290  -->  00:03:18,340
that you have a small test network, a lab,
91

91

00:03:18,340  -->  00:03:20,508
or at the very least, a single machine that you're going to
92

92

00:03:20,508  -->  00:03:23,350
use for testing new patches before you deploy
93

93

00:03:23,350  -->  00:03:25,080
across your entire network.
94

94

00:03:25,080  -->  00:03:27,450
After all many of our organizations have unique
95

95

00:03:27,450  -->  00:03:28,930
configurations within our networks,
96

96

00:03:28,930  -->  00:03:31,130
and these patches can break things.
97

97

00:03:31,130  -->  00:03:34,100
So when a manufacturer tries to attempt to make sure that
98

98

00:03:34,100  -->  00:03:35,870
patch is not going to harm our systems,
99

99

00:03:35,870  -->  00:03:37,280
they cannot guarantee this
100

100

00:03:37,280  -->  00:03:39,760
because everyone has different configurations.
101

101

00:03:39,760  -->  00:03:41,824
Instead it is better to find out if a patch is causing
102

102

00:03:41,824  -->  00:03:44,900
issues in your lab environment before you push it across
103

103

00:03:44,900  -->  00:03:48,230
10,000 workstations across the entire enterprise network.
104

104

00:03:48,230  -->  00:03:50,440
Because if you do that, you're going to have a lot of end users
105

105

00:03:50,440  -->  00:03:53,410
yelling and screaming at you when their systems crash.
106

106

00:03:53,410  -->  00:03:55,540
Step three, implementation.
107

107

00:03:55,540  -->  00:03:56,850
After you've tested the patch,
108

108

00:03:56,850  -->  00:03:58,470
it's now going to be time to deploy it
109

109

00:03:58,470  -->  00:03:59,970
to all of the workstations and servers
110

110

00:03:59,970  -->  00:04:01,190
that are going to need it.
111

111

00:04:01,190  -->  00:04:03,290
You can do this manually by going to each system
112

112

00:04:03,290  -->  00:04:04,710
and installing it yourself,
113

113

00:04:04,710  -->  00:04:07,100
or you can do it automatically by deploying
114

114

00:04:07,100  -->  00:04:09,370
that patch to your client, workstations and servers,
115

115

00:04:09,370  -->  00:04:11,330
using one of those tools like SCCM
116

116

00:04:11,330  -->  00:04:12,650
that we talked about earlier.
117

117

00:04:12,650  -->  00:04:14,370
This way, it will install the patch
118

118

00:04:14,370  -->  00:04:16,200
and move it into production for you.
119

119

00:04:16,200  -->  00:04:18,170
If you have a small network of just a few clients
120

120

00:04:18,170  -->  00:04:20,830
or servers, you may choose to install things manually
121

121

00:04:20,830  -->  00:04:23,390
and do it that way because it's really quick and easy,
122

122

00:04:23,390  -->  00:04:24,780
and it costs no additional money
123

123

00:04:24,780  -->  00:04:26,400
by buying a third party tool.
124

124

00:04:26,400  -->  00:04:27,960
But if you have a large network,
125

125

00:04:27,960  -->  00:04:30,150
you're going to want to use some kind of tool.
126

126

00:04:30,150  -->  00:04:32,800
Microsoft provides this one known as SCCM,
127

127

00:04:32,800  -->  00:04:35,290
the Microsoft System Center Configuration Manager,
128

128

00:04:35,290  -->  00:04:37,740
but you can also use third-party management tools
129

129

00:04:37,740  -->  00:04:39,500
with a lot more features and additional
130

130

00:04:39,500  -->  00:04:41,280
abilities if you want to.
131

131

00:04:41,280  -->  00:04:43,640
Now, some organizations rely on automatic updates
132

132

00:04:43,640  -->  00:04:45,300
from the Windows update system,
133

133

00:04:45,300  -->  00:04:47,810
but others decide they want to have complete control over
134

134

00:04:47,810  -->  00:04:49,300
the installation of patches.
135

135

00:04:49,300  -->  00:04:51,990
For large organizations, it is highly recommended
136

136

00:04:51,990  -->  00:04:54,000
that you essentially manage all your updates
137

137

00:04:54,000  -->  00:04:55,300
through an update server
138

138

00:04:55,300  -->  00:04:57,740
instead of using the Windows update tool.
139

139

00:04:57,740  -->  00:05:00,140
This will allow you to test the patch prior to deploying it
140

140

00:05:00,140  -->  00:05:01,780
across your entire environment.
141

141

00:05:01,780  -->  00:05:03,770
To disable Windows update on your clients,
142

142

00:05:03,770  -->  00:05:06,040
you simply need to disable the Windows update service
143

143

00:05:06,040  -->  00:05:08,620
from running automatically on those workstations.
144

144

00:05:08,620  -->  00:05:11,080
If you have a lot of mobile devices throughout your network,
145

145

00:05:11,080  -->  00:05:12,240
you also to figure out how you're going
146

146

00:05:12,240  -->  00:05:14,470
to do patch management for those devices.
147

147

00:05:14,470  -->  00:05:16,150
The easiest way to do this is by using
148

148

00:05:16,150  -->  00:05:18,210
a mobile device manager or MDM,
149

149

00:05:18,210  -->  00:05:20,260
which works like one of these patch management servers,
150

150

00:05:20,260  -->  00:05:22,350
but has additional features as well.
151

151

00:05:22,350  -->  00:05:24,290
Alright, now, when you comes to testing,
152

152

00:05:24,290  -->  00:05:26,650
you may not have your own dedicated test network
153

153

00:05:26,650  -->  00:05:29,760
or lab environment to use, but you still need to do testing.
154

154

00:05:29,760  -->  00:05:31,440
So what are you going to do?
155

155

00:05:31,440  -->  00:05:33,100
Well, one thing you can do is split up
156

156

00:05:33,100  -->  00:05:35,660
your production network into smaller groups.
157

157

00:05:35,660  -->  00:05:37,220
Organizations I've led in the past,
158

158

00:05:37,220  -->  00:05:38,503
we use the concept of patch ring
159

159

00:05:38,503  -->  00:05:40,550
when we deploy out new patches.
160

160

00:05:40,550  -->  00:05:43,520
In patch ring 1, we have 10 or 20 end user machines
161

161

00:05:43,520  -->  00:05:45,280
that will deploy our patches to first.
162

162

00:05:45,280  -->  00:05:47,270
If it doesn't break anything on those machines,
163

163

00:05:47,270  -->  00:05:49,240
then we'll move out into patch ring 2
164

164

00:05:49,240  -->  00:05:51,080
which has 100 or 200 people.
165

165

00:05:51,080  -->  00:05:53,100
And this'll include things like our system administrators,
166

166

00:05:53,100  -->  00:05:55,320
and our service desk workstations so we can instantly
167

167

00:05:55,320  -->  00:05:57,220
figure out if things are going wrong.
168

168

00:05:57,220  -->  00:05:58,580
If that works successfully,
169

169

00:05:58,580  -->  00:06:00,240
we'll then go in to patch ring 3,
170

170

00:06:00,240  -->  00:06:02,740
which contains 1000 or 2000 machines.
171

171

00:06:02,740  -->  00:06:04,780
And finally, we'll move on to patch ring 4,
172

172

00:06:04,780  -->  00:06:06,090
which includes everybody else,
173

173

00:06:06,090  -->  00:06:08,600
and then maybe 10 or 20,000 machines.
174

174

00:06:08,600  -->  00:06:10,461
Now the benefit of doing the deployments this way as we move
175

175

00:06:10,461  -->  00:06:12,030
through the various patch rings,
176

176

00:06:12,030  -->  00:06:14,350
is that if there is an issue, I'm only affecting
177

177

00:06:14,350  -->  00:06:17,350
a smaller group of users before I break all the users
178

178

00:06:17,350  -->  00:06:18,183
on the network.
179

179

00:06:18,183  -->  00:06:21,370
If I did everybody at once, I'd have 20 or 30,000 people
180

180

00:06:21,370  -->  00:06:23,000
who are complaining when things break,
181

181

00:06:23,000  -->  00:06:24,360
but by doing it in these smaller steps,
182

182

00:06:24,360  -->  00:06:27,020
I only have 10 or 15 people who are yelling at me,
183

183

00:06:27,020  -->  00:06:28,830
and I can fix things quicker.
184

184

00:06:28,830  -->  00:06:31,000
Alright, step four, auditing.
185

185

00:06:31,000  -->  00:06:32,860
Now, auditing is important to understand
186

186

00:06:32,860  -->  00:06:34,920
because you have to understand the client status
187

187

00:06:34,920  -->  00:06:37,030
after you conduct your patch deployment.
188

188

00:06:37,030  -->  00:06:39,420
So I pushed out the patch, did it work?
189

189

00:06:39,420  -->  00:06:41,410
During auditing, you're going to be able to scan the network
190

190

00:06:41,410  -->  00:06:44,370
and determine if that patch that you pushed out to install
191

191

00:06:44,370  -->  00:06:46,860
actually installed properly, or are there any kind
192

192

00:06:46,860  -->  00:06:48,940
of unexpected failures that may have happened,
193

193

00:06:48,940  -->  00:06:51,000
and that meant that the patch wasn't really installed,
194

194

00:06:51,000  -->  00:06:53,070
or isn't doing the protection it's supposed to do?
195

195

00:06:53,070  -->  00:06:54,610
Again, if you're using a tool like
196

196

00:06:54,610  -->  00:06:57,870
the Microsoft System Center Configuration Manager, SCCM,
197

197

00:06:57,870  -->  00:06:59,680
or a third-party management tool,
198

198

00:06:59,680  -->  00:07:01,910
you'll be able to conduct scanning and verification of your
199

199

00:07:01,910  -->  00:07:04,470
workstations and servers to ensure that the patches have
200

200

00:07:04,470  -->  00:07:06,880
been installed properly and with no issues.
201

201

00:07:06,880  -->  00:07:08,990
Now, if you're using Linux or OS X,
202

202

00:07:08,990  -->  00:07:11,470
they also have built in patch management systems.
203

203

00:07:11,470  -->  00:07:14,410
For example, Red Hat Linux uses a package manager
204

204

00:07:14,410  -->  00:07:17,620
to deploy RPMs, which are packages of patches
205

205

00:07:17,620  -->  00:07:19,160
to your servers and workstations.
206

206

00:07:19,160  -->  00:07:22,180
So the same concepts and principles are going to apply here.
207

207

00:07:22,180  -->  00:07:24,490
Now, in addition to conducting patch management across our
208

208

00:07:24,490  -->  00:07:26,930
workstations and servers, it's also important for us
209

209

00:07:26,930  -->  00:07:29,800
to conduct firmware management for our network devices.
210

210

00:07:29,800  -->  00:07:31,860
After all, all of our network devices
211

211

00:07:31,860  -->  00:07:33,490
are running some form of software,
212

212

00:07:33,490  -->  00:07:36,130
and this is known as firmware inside of our routers,
213

213

00:07:36,130  -->  00:07:37,600
our switches, our firewalls,
214

214

00:07:37,600  -->  00:07:39,530
and our other network appliances.
215

215

00:07:39,530  -->  00:07:41,631
If your network devices don't contain the latest and most
216

216

00:07:41,631  -->  00:07:43,340
up-to-date firmware versions,
217

217

00:07:43,340  -->  00:07:45,460
then you could have security vulnerabilities and software
218

218

00:07:45,460  -->  00:07:47,920
bugs that could be exploited by an attacker.
219

219

00:07:47,920  -->  00:07:50,020
If you look at the common vulnerabilities and exposures
220

220

00:07:50,020  -->  00:07:52,530
or CVE website, you're going to see a long list
221

221

00:07:52,530  -->  00:07:53,720
of vulnerabilities that we have
222

222

00:07:53,720  -->  00:07:56,080
for all sorts of different networking devices.
223

223

00:07:56,080  -->  00:07:58,290
Just select the Cisco devices, and you'll see a long
224

224

00:07:58,290  -->  00:08:00,020
laundry list of those that have been patched
225

225

00:08:00,020  -->  00:08:01,330
and fixed over time.
226

226

00:08:01,330  -->  00:08:03,420
So just like you need to patch your operating system
227

227

00:08:03,420  -->  00:08:05,040
for a Windows or Linux computer,
228

228

00:08:05,040  -->  00:08:06,830
you also need to update the operating system
229

229

00:08:06,830  -->  00:08:08,330
of your network devices.
230

230

00:08:08,330  -->  00:08:11,606
In a Cisco device, this is known as the Cisco IOS
231

231

00:08:11,606  -->  00:08:13,820
or Internetwork Operating System.
232

232

00:08:13,820  -->  00:08:15,600
Now to update the IOS version,
233

233

00:08:15,600  -->  00:08:18,740
you need to flash the firmware on that networking device.
234

234

00:08:18,740  -->  00:08:21,432
Some manufacturers like Cisco provide a centralized method
235

235

00:08:21,432  -->  00:08:24,140
of conducting firmware management inside your enterprise
236

236

00:08:24,140  -->  00:08:26,710
network, and this helps with our patch management.
237

237

00:08:26,710  -->  00:08:29,930
For example, Cisco use the Cisco UCS Manager
238

238

00:08:29,930  -->  00:08:31,830
to centralize the management of resources and devices
239

239

00:08:31,830  -->  00:08:33,930
and to conduct firmware management
240

240

00:08:33,930  -->  00:08:36,900
for your server network interfaces and server devices.
241

241

00:08:36,900  -->  00:08:39,430
There's also third-party tools like DeviceExpert
242

242

00:08:39,430  -->  00:08:41,500
by ManageEngine that allow you to upgrade,
243

243

00:08:41,500  -->  00:08:44,220
downgrade and manage the configuration of the firmware
244

244

00:08:44,220  -->  00:08:45,670
for all of your network devices,
245

245

00:08:45,670  -->  00:08:48,520
using automation, orchestration and scripting.
246

246

00:08:48,520  -->  00:08:50,660
The bottom line here is that you need to do firmware
247

247

00:08:50,660  -->  00:08:53,090
management, to ensure you have the right firmware versions
248

248

00:08:53,090  -->  00:08:55,520
loaded onto those network devices, to ensure that you have
249

249

00:08:55,520  -->  00:08:57,470
the right security for those devices,
250

250

00:08:57,470  -->  00:08:59,440
just like we do with our workstations and clients,
251

251

00:08:59,440  -->  00:09:00,890
when we use patch management.
