August 5, 2008 6:00 AM PDT

Microsoft to give partners heads-up on security vulnerabilities

Microsoft will be giving companies that sell security software and services to its customers a sneak peek at the technical details of the vulnerabilities in Microsoft software before the company releases its monthly "Patch Tuesday" updates.

The new Microsoft Active Protections Program, set to be announced at the Black Hat security conference on Tuesday, is designed to give software vendors a chance to prepare updates to their software before attackers have a chance to reverse engineer Microsoft's security patch and create an exploit.

"It's essentially a race between the attackers and the protectors," said Andrew Cushman, who runs the Microsoft Security Response Center. The program will "give a head start to software providers delivering security features to our mutual customers."

"It will save (vendors) the work of reverse engineering the patch and identifying where the vulnerability is and what triggers the exploitability," he said.

Cushman did not say how vendors would be notified or how much lead time they would get. Software companies that provide protection against host-based or network-based attacks will have to apply for membership to the program and be accepted. They and Microsoft will then be under mutual non-disclosure agreements, he said.

"The goal is to give it to them so they can have updates available as close to 10 a.m. as possible" on the second Tuesday of every month, Cushman said.

The program will begin in October. Microsoft has already floated the idea by IBM/ISS, TippingPoint and Juniper, he said.

Microsoft also will be providing an Exploitability Index in its monthly security bulletins beginning in October that will help organizations prioritize vulnerabilities by assigning one of three ratings to each one based on the likelihood of exploits being developed. The ratings from most severe to least severe are: "exploitation is likely to occur and to be reliable," "exploitation is likely to occur but with inconsistent reliability" and "exploitation is unlikely to occur," according to Cushman.

Click here for full coverage of Black Hat 2008.

Recent posts from News - Security
Brazilian charged in U.S. in connection with operating botnet
Psychological profiling on the Web
Security expert: DNS attacks are happening
Malicious Flash ads attack, spread via clipboard
Hacker exposes alleged Olympics age fraud
Add a Comment (Log in or register) 4 comments (Page 1 of 1)
by n3td3v August 5, 2008 8:17 AM PDT
Verbal contracts of non-disclosure agreements don't work, you need a new law in place, which I call the responsible disclosure act, http://seclists.org/fulldisclosure/2008/Jul/0439.html to enforce the agreement by a law if the agreement is broken. Or are you guys just gonna do another "oops the cat's out the bag" again like what happened with the verbal contract agreement Dan Kaminsky had with everyone before a blog entry leaked the vulnerability by *accident*. Is this Microsoft agreement of non-disclosure actually enforceable by any current law? If not a new law is needed to be drawn up, see the link above, or this "Microsoft Active Protection Program" is gonna turn out a complete shambles.
Reply to this comment View reply
by jcorio August 5, 2008 10:11 AM PDT
Yeah... but this isn't like the whole Matasano/Kaminsky thing... these are actual businesses that have partnered together previously and have well vetted non-disclosure agreements and contracts in place. These are (and have been many times) enforcable by law.
Reply to this comment
by The_Decider August 5, 2008 11:19 AM PDT
If it was to be announced at Black Hat, then why did they announce it earlier?

This is a positive development, however, wouldn't it be better if MS spent their time creating an OS that isn't exploited every minute of every day?
Reply to this comment
Powered by Jive Software
advertisement
  • About News - Security

  • Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader
Google
Yahoo
MSN

Most popular stories

  1. Google's search secret: It gets rid of you

  2. Developer creates copy-paste tech for iPhone

  3. Will Wright on the origins of 'Spore'

  4. Palm Treo Pro: Not digging it

  5. American Airlines launches in-flight Wi-Fi

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Defense in Depth by Robert Vamosi

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

advertisement
On MovieTome: TRANSFORMERS 2 SPOILERS!
Advanced
search
Advanced
search
Visit other CBS Interactive sites