---
title: "Virtual Patching Part II: What Makes It So Darn Tricky?"
description: These very simple, but at one point real-world examples, help explain why performing virtual patching at the network is so difficult.
image: https://businessinsights.bitdefender.com/hs-fs/hub/341979/file-610239943.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#Enterprise Security](https://businessinsights.bitdefender.com/topic/enterprise-security) [#Threat Research](https://businessinsights.bitdefender.com/topic/threat-research)

 By [**Shaun Donaldson**](https://businessinsights.bitdefender.com/author/shaun-donaldson) / Mar 26, 2014

# Virtual Patching Part II: What Makes It So Darn Tricky?

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/what-makes-virtual-patching-tricky&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/what-makes-virtual-patching-tricky&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/what-makes-virtual-patching-tricky&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/what-makes-virtual-patching-tricky&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/what-makes-virtual-patching-tricky&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/what-makes-virtual-patching-tricky&utm_medium=social&utm_source=facebook)

In my last blog [post ](https://businessinsights.bitdefender.com/what-is-virtual-patching?hsLang=en-us)I began a conversation about **virtual patching**. In this post, I’ll further the discussion by talking about why effective virtual patching at the network is so **difficult**.

The story really begins by considering **context**, or really, *the lack thereof.* If a **vulnerability** exists in an application (a web application, or a browser) there is a certain context associated with the application that is **difficult to be aware of** at a point outside of the application. The simplest example is a session. A web application may create a session when a user logs-in, destroying the session after a period of inactivity, or when a user logs-out (*and when was the last time you logged-out instead of just closing the browser window?*).

The browser sends cookies containing some sort of identifier that the web application uses to associate the browser request with a session – for example, showing you your bank account information instead of someone else’s. If someone in the middle figures-out how to grab those cookies, they can try to fool the web application into believing they are the end-user. However, the web application has its session context – and if the session is no longer valid at the web application, the cookies are useless.

## **It’s all about context**

The problem is that something like a network intrusion detection system can’t access that session context unless it somehow tracks it on its own (creating its own context). From a performance perspective, that can be taxing,especially since network traffic is sensitive to latency. Robust web application firewalls often try to “*learn*” the application before enforcing rules, just by looking at “*normal*” network traffic.

That can be very complicated, and therefore prone to false positives, and also assumes that what it “*learns*” as normal isn’t actually bad behavior. Oh, and then the web application is updated… leading to another learning cycle.

![Virtual_Patching_tricky](https://businessinsights.bitdefender.com/hs-fs/hub/341979/file-610239943.jpg?width=719&name=file-610239943.jpg "Virtual_Patching_tricky")

Another web application example is **SQL** **injection**. SQL injection involves providing input, say – entries on a form that is submitted to the application, which **trick** the application into doing something that it shouldn’t. A classic example (and a very simple one) is if at login, a web application asks the database to:

SELECT \* FROM “users” WHERE username=*”johnd*” and password=*”p@ssword”*;

Basically, if it returns something, there is an entry in the “*users*” table with that username and password. If when filling-in the form the data is tampered with, the application doesn’t normalize the input, and so on, the query may look like:  
SELECT \* FROM “users” WHERE username=”*johnd*” and password=”*injection*” or 1=1; -- “;

By putting ”*injection*” or 1=1; -- in the password field, the application is tricked into always returning true because one does equal one. Perhaps changing that behavior will take some time, so we’ll set-up a filter at the network to look for input that contains or 1=1; --. The attacker instead uses or 2=2; --, 3=3, 4=4… and so on. There are **infinite variations**, in other words. **That makes filtering for SQL injection attacks at the network level difficult, and error-prone (false positives and false negatives).**

On the other hand, going to where the web application is running, or even the database, can be much more effective because context is available. Should a login page be updating something in the database, or deleting something? Probably not – simple contextual awareness then eliminates swaths of SQL injection possibilities.

## **Simple vulnerabilities, complex risks**

On the client side, a straightforward example follows a dead-simple **exploit vulnerability** from a few years back. The vulnerability was in a JavaScript create.TextRange() bit of code ([http://www.securityfocus.com/bid/17196/exploit](http://www.securityfocus.com/bid/17196/exploit)). The details aren’t important, just know that a=r.createTextRange() is the important piece.

As with the simple SQL injection example, it’s tempting to declare it can be detected at the network by looking for that string heading toward a vulnerable IE browser. Well, without context, it’s difficult to know if it is a vulnerable IE browser, for starters. Second, because browsers are so helpful in their willingness to try to parse anything thrown at them, an **attacker** can split up that string, and ask the browser to combine the multiple strings to form a=r.createTextRange() when the code is executed at the browser. Again, **there are nearly infinite ways to jumble it up, making the creation of a *“specific enough, but not too specific”* filter applied to network traffic impossible.**

These very simple, but at one point real-world examples help explain why performing virtual patching at the network is so ***difficult***. It all seems rather fatalistic, so in my next post, I’ll turn talk about the advantages of having context to brighten things up.

As a final note, if you are running a version of IE anywhere on your network that is vulnerable to the example I used, you’ve got far bigger problems to deal with than fiddling with virtual patching!

*Stay tuned for more on this topic and our upcoming **Paper about Active Virus Control (AVC)**, our approach to **Host Intrusion Prevention (HIPS)**.*

 

 

                       [![Subscribe to Business Insights](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/86b5d155-977c-40ac-aa45-e9804451f03c.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/86b5d155-977c-40ac-aa45-e9804451f03c)

 

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/bluekeep-exploit-code-released-blocked-by-hypervisor-introspection?hsLang=en-us>

### [BlueKeep Exploit Code Released, Blocked by Hypervisor Introspection](https://businessinsights.bitdefender.com/bluekeep-exploit-code-released-blocked-by-hypervisor-introspection?hsLang=en-us)

<https://businessinsights.bitdefender.com/technical-advisory-immediately-patch-your-vmware-esxi-servers-targeted-by-opportunistic-threat-actors?hsLang=en-us>

### [Technical Advisory: Immediately Patch Your VMware ESXi Servers Targeted by Opportunistic Threat Actors](https://businessinsights.bitdefender.com/technical-advisory-immediately-patch-your-vmware-esxi-servers-targeted-by-opportunistic-threat-actors?hsLang=en-us)

<https://businessinsights.bitdefender.com/hypervisor-introspection-defeated-enternalblue-a-priori?hsLang=en-us>

### [Hypervisor Introspection defeated Eternalblue a priori](https://businessinsights.bitdefender.com/hypervisor-introspection-defeated-enternalblue-a-priori?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Shaun Donaldson",
    "url" : "https://businessinsights.bitdefender.com/author/shaun-donaldson"
  },
  "dateModified" : "2023-03-26T12:33:40.709Z",
  "datePublished" : "2014-03-26T15:17:00.000Z",
  "headline" : "Virtual Patching Part II: What Makes It So Darn Tricky?",
  "image" : [ "https://businessinsights.bitdefender.com/hs-fs/hub/341979/file-610239943.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/what-makes-virtual-patching-tricky",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```