Endpoint attacks can come from any direction and many sources. Just consider the reported vulnerabilities found in Apache Struts and the damage caused by WannaCry and Petya. Companies need to stay one step ahead of endpoint attacks, but they struggle due to a lack of visibility of endpoint status, the complexity of investigations and ineffective remediation.

Let’s consider the Apache Struts vulnerability in more detail. Some versions of the Apache Struts web application development framework allow attackers to execute arbitrary code in the context of the affected application. See the related S2-052 Apache Security Bulletin and the IBM X-Force Exchange security alerts page for more technical details on how the vulnerability can be exploited, what version of Apache Struts is affected and the best-recommended remediation actions to take.

Register for the Sept. 27 webinar: 3 Tips for Effective Endpoint Security

How Do You Know If Your Endpoints Are Susceptible?

What if you’re vulnerable and you don’t even know it? Security and IT organizations must be able to see, understand and act on endpoint threats fast. In the case of Apache Struts, you must be able to quickly identify every computer where there could be applications exploiting Apache Struts and determine which versions of the framework are installed on which servers or computer endpoint devices. But how do you know if you’ve already been impacted by a security vulnerability? Where do you begin?

Because the Apache Struts runtime library is not deployed in a dedicated directory or file system path, the malicious, arbitrary code may be located anywhere within the file system. As a result, you must first scan the entire file system on every endpoint, including Apache development environments, to determine whether the rogue executable file exists.

Mitigating Endpoint Attacks

Once you know which servers are affected, you need to take the actions suggested by the security bulletins to remediate the vulnerability, such as but not limited to updating software on all the affected endpoints. This includes updating Apache and other applications that leverage the Apache Struts runtime library. These applications must then be recompiled and redeployed. You may not be able to shut down or quarantine the entire server if it is running other critical applications that are not affected by this vulnerability. The IT security and operations teams need to decide how to best remediate based on which servers are affected within their environments.

According to Forrester Research, “Endpoint security represents the front line in your fight against cyberattackers. Breaches have become commonplace among enterprises, and your employee endpoints and servers are targeted more than any other type of asset.” Solutions such as IBM BigFix can help IT security and operations teams put in place the required remediation actions based on the organization’s environment and risk mitigation assessments.

With the ability to clearly see the status of all endpoints across the enterprise and use guided investigations to understand both the scope of an attack and the specific remediation steps needed to contain the threat, security teams can act quickly and decisively to protect valuable assets and reduce the organization’s attack surface.

Read the white paper: Transforming endpoint security — Going far beyond attack detection

More from Endpoint

Unified endpoint management for purpose-based devices

4 min read - As purpose-built devices become increasingly common, the challenges associated with their unique management and security needs are becoming clear. What are purpose-built devices? Most fall under the category of rugged IoT devices typically used outside of an office environment and which often run on a different operating system than typical office devices. Examples include ruggedized tablets and smartphones, handheld scanners and kiosks. Many different industries are utilizing purpose-built devices, including travel and transportation, retail, warehouse and distribution, manufacturing (including automotive)…

Virtual credit card fraud: An old scam reinvented

3 min read - In today's rapidly evolving financial landscape, as banks continue to broaden their range of services and embrace innovative technologies, they find themselves at the forefront of a dual-edged sword. While these advancements promise greater convenience and accessibility for customers, they also inadvertently expose the financial industry to an ever-shifting spectrum of emerging fraud trends. This delicate balance between new offerings and security controls is a key part of the modern banking challenges. In this blog, we explore such an example.…

Endpoint security in the cloud: What you need to know

9 min read - Cloud security is a buzzword in the world of technology these days — but not without good reason. Endpoint security is now one of the major concerns for businesses across the world. With ever-increasing incidents of data thefts and security breaches, it has become essential for companies to use efficient endpoint security for all their endpoints to prevent any loss of data. Security breaches can lead to billions of dollars worth of loss, not to mention the negative press in…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today