LinuxQuestions.org
Support LQ: Use code LQ3 and save $3 on Domain Registration
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 12-22-2011, 03:39 PM   #1
Linux_Kidd
Member
 
Registered: Jan 2006
Location: USA
Posts: 342

Rep: Reputation: 38
Yum repository question


this is pseudo security related.

i am looking for any resource which can tell me all of the package updates per time period for any given repository/distro. as example, i would like to know of all the packages available from a specific repo which ones have updates available since last month, and of those which are security related.

as example, i had a rhel 5.7 box that was not pacthed, so since about 12Oct2011 the box went from fully patched to needing 33 package updates, 12 of those security related. total packages installed is 425. that’s 7.7% of total installed packages in just ~2 months (2.8% security related). that’s a rate of ~3.85%/month total, 1.4%/month security related.

i created and run a script that runs every wed generating a report that lists needed updates and highlightling those that are security related. its not obvious from my reports if it will reach a plateau, if it will continue at this rate, or if this observation is linear with varying # of total installed packages, hence why i am looking for some sort of online resource for me to do some analysis.

this info is interesting, it gives an idea as to the growing known-risk exposure that is present between patching cycles. i suspect an up-to-date scanner like Nessus and others might give similar data, but these tools also rely on being up-to-date, hence why i am querying the repo via yum to get realtime info.

all just more tidbit info to enforce proper patch management program, etc.
 
Old 01-02-2012, 11:35 PM   #2
mrdvt92
LQ Newbie
 
Registered: Apr 2006
Posts: 6

Rep: Reputation: 0
The patches slow down but never really stop until the OS is end-of-life.

RHEL is good in that they try VERY hard to not break any APIs. Fedora is not so kind as they have a different goals where progress is number one priority.


mrdvt92
 
Old 01-25-2012, 09:26 AM   #3
Linux_Kidd
Member
 
Registered: Jan 2006
Location: USA
Posts: 342

Original Poster
Rep: Reputation: 38
so, just wanted to share 19 weeks worth of data for a rhel5 that hasnt been patched in 17 weeks.

line chart just shows total required patches vs those are security patches. the stacked chart is security on top of non-security patches (so total stack = total needed, etc). interesting results.

one odd thing i noticed was between week 17 and 18:

week#,total-missing,security-related
17,35,14
18,35,16

this seems to suggest that between wk 17 & 18 two non-security-related patches turned into security-related ???
Attached Images
File Type: png line-total.PNG (11.4 KB, 2 views)
File Type: png stacked-cylinder-sec-vs-non-sec.PNG (44.0 KB, 2 views)

Last edited by Linux_Kidd; 01-25-2012 at 10:54 AM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Yum repository related question ragsnayak Red Hat 2 12-04-2008 02:46 AM
Yum repository related question ragsnayak Linux - Software 7 12-04-2008 12:36 AM
yum antivirus and repository question ehartanto Linux - Enterprise 9 10-30-2008 02:21 AM
Redhat 5.1 Yum Repository vs Fedora x.x Yum Repository lead2gold Linux - Software 1 05-22-2008 02:19 PM


All times are GMT -5. The time now is 12:11 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration