Intel Meltdown / Spectre Patch Tested on Avigilon, Exacq and Milestone VMSes

Author: IPVM Team, Published on Jan 23, 2018

Significant concern exists about the impact on VMS servers and video surveillance systems of patching the Meltdown and Spectre flaws. Generally, reports have claimed a significant increase in CPU loads, though the amounts have varied depending on the source and services being used. This could be very problematic for VMS servers as it risks problems in recording, watching or playing back video.

Meltdown / Spectre Summary

Meltdown is a flaw in protections allowing unauthorized applications to access OS kernel protected memory. Spectre allows unauthorized applications to trick other programs into divulging private data. For technical details on these, see The Meltdown and Spectre CPU Bugs, Explained or various other online tech sources.

How To Patch

Users may see if their Windows machine is vulnerable using PowerShell, following the steps in this guide.

If so, in order to avoid both of these vulnerabilities, users must install two updates:

  • Windows Update KB4056892: This update should have been included in regular Windows Updates as of early January. This fixes the Meltdown vulnerability.
  • BIOS update: To fix the Spectre vulnerability, users must update their system BIOS, provided by their hardware manufacturer.

However, many devices have not yet received a BIOS update. Out of four different hardware manufacturers we checked (Acer, Asus, HP, and Intel NUCs), only Intel had released a BIOS update for our machines.

Tests Performed

IPVM measured CPU load of server and client processes prior to applying Windows and BIOS updates, and again after updating, using two configurations:

  • Recording only, 25 cameras, ~150 Mb/s
  • Recording and viewing, 10 cameras, ~30 Mb/s

Test Machine Specs

IPVM tested on three separate machines, all with the same hardware configuration, as follows:

  • Operating System: Windows 10 Pro 64-bit (10.0, Build 16299) (16299.rs3_release.170928-1534)
  • BIOS: RYBDWi35.86A.0350.2015.0812.1722 (pre-update)/RYBDWi35.86A.0368.2017.1220.0950 (post-update)
  • Processor: Intel(R) Core(TM) i7-5557U CPU @ 3.10GHz (4 CPUs), ~3.1GHz
  • Memory: 8192MB RAM

Note that these machines are fairly high spec, with relatively new processors (1-2 generations old). Older generation processors and lower spec machines are likely to see a greater impact.

Inside this report, we examine the results achieved across Avigilon, Exacq and Milestone plus our recommendations.

*********** ******* ****** ***** *** ****** ** *** ******* *** video ************ ******* ** ******** *** ******** *** ******* *****. Generally, ******* **** ******* * *********** ******** ** *** *****, though *** ******* **** ****** ********* ** *** ****** *** services ***** ****. **** ***** ** **** *********** *** *** servers ** ** ***** ******** ** *********, ******** ** ******* back *****.

Meltdown / ******* *******

******** ** * **** ** *********** ******** ************ ************ ** access ** ****** ********* ******. ******* ****** ************ ************ ** trick ***** ******** **** ********* ******* ****. *** ********* ******* on *****, ****** ******** *** ******* *** ****, *********** ******* ***** ****** **** *******.

How ** *****

***** *** *** ** ***** ******* ******* ** ********** ***** PowerShell,********* *** ***** ** **** *****.

** **, ** ***** ** ***** **** ** ***** ***************, users **** ******* *** *******:

  • ******* ****** *********: **** ****** ****** **** **** ******** ** regular ******* ******* ** ** ***** *******. **** ***** *** Meltdown *************.
  • **** ******: ** *** *** ******* *************, ***** **** ****** their ****** ****, ******** ** ***** ******** ************.

*******, **** ******* **** *** *** ******** * **** ******. Out ** **** ********* ******** ************* ** ******* (****, ****, HP, *** ***** ****), **** ***** *** ******** * **** update *** *** ********.

Tests *********

**** ******** *** **** ** ****** *** ****** ********* ***** to ******** ******* *** **** *******, *** ***** ***** ********, using *** **************:

  • ********* ****, ** *******, ~*** **/*
  • ********* *** *******, ** *******, ~** **/*

Test ******* *****

**** ****** ** ***** ******** ********, *** **** *** **** hardware *************, ** *******:

  • ********* ******:******* ** *** **-*** (**.*, ***** *****) (*****.***********.******-****)
  • ****:********.***.****.****.****.**** (***-******)/********.***.****.****.****.**** (****-******)
  • *********:*****(*) ****(**) **-***** *** @ *.***** (* ****), ~*.****
  • ******:****** ***

**** **** ***** ******** *** ****** **** ****, **** ********** new ********** (*-* *********** ***). ***** ********** ********** *** ***** spec ******** *** ****** ** *** * ******* ******.

****** **** ******, ** ******* *** ******* ******** ****** ********, Exacq *** ********* **** *** ***************.

[***************]

Test *******

** *** *****, ******** ****** **** ** ***** *** ******* vulnerability *** * *********** ****** ** *** ****, ********** *** load ** ********* ******** ** ** **** **-**%. ****** ** server **** **** ******* **** ** ******** ***** *** **** more ***********, ****** ******** *** **** ** *** ****** ***** systems ***** ******** *** ***** (** ******** ** **-**% ****). Applying *******' ******** ****** ** ***** ******** ***** *** * negligible ******, ********** **** **** **** *%.

****** *******, ** *** ** *** ******* **** ***** *******/******** updates, **** ** ******* ******, **** ******* *****, ******** ** video, ** ***** *** ************ ***** *** ***** **** **********. However, **** **** *** ******* *** **** **** ** **** testing *** ***** ***** **% ***********. ***** **** ****** ********** systems ** ***** **** ******* *** *** ****** ** ***** camera ******/***********.

***************

******* ** *** *********** ****** ** **** ******* ** *** load, ** ******** ********* **** ***** ** ****** **********/****** ****** count ******* ****** ***** ****** *** ******** ***** ** ********. Those ********* ******* ** **-**% **** *** ****** ** ******** to **-***%, **** *** ********* *** ****** **** ******.

***** **** *** ****** *****/********** ******* *** ****** ** *** little *********** ********** ****** **** ******* ******* ** *** ****** machine.

Intel ***** ******** ******* - ****** *****

******* *** **** ******* **** ****** ****** ****** ** ******* machines (****: **** *** *** ********** ****, *** ** *** be ******** *********). ***** ******** * ********* ** ******* **** that**** *** ***** ******** **** ********** **** ****** **** ******* ******* ****. ******* *********** *** that *** ******* ******* **** **** ******* ******* *********** *******, and ***** ** ************ ******** ** ******** ** **** **** the ******* ******* ** *** **** **** ** *********** *******.

Biggest ******: **** ******

** ***** ** ***** ****** *** ******** *** ******* ***************, users **** ***** **** ******* ******* *** **** *******. ** these ***, *** **** ****** *** * *********** ****** ** CPU ****, ***** ******* ******* *** ******* ******, **** ***** 1% ** *** ***** ******, **** ********* *** *******.

Significant ****** ** **** ********** ****

** *** ***** ** ** ****** *******, ~*** **/* ***** throughput, ****** ******* *** **** ********* ************* ***** ******** *** BIOS ** **** *******, **** *********** ************ ********** ** ~*% and ********* ******** ********* ** ~**%.

**** **** ** ******** ** ****** ** *********** ** ****** VMS ****** ******* (******* ******, **** *******, ********/******* *****, ***.), but ***** **** ****** ********** *** *** ****** ** **** jumps ***** ********.

Low ********** ********* *******

******* **** ** ******* ** ***** ** **/* *****, ****** load *** ***** ********* **** *****, *** *************** ****** **** 24 ****** *******, **** ***** ********** ** *% **** (* 50% ********) *** ********* ** *% (* ~**% ********). *******, Avigilon ******* ****** ****** *************, **** ~*% ** *%, *** as **** ****** ********** *******, ***** ********* *** *** ****** in ********** *********** ******.

Live **** ******* *** ******

*** **** ********* *** ***** ******* ***** ***** ******* **** far **** ***********, **** ******** *** ***** ********** ** **-**% when **** ******* ** ******* **** *** ******* ** *** recording ******. ********* ********* ** ***** *** **** *** **** percentage, *** * *************** ******* ******.

Test ********* ****** ********

***** ** *** ******* ***** ** *****'* **** ******* **** would ******* ***** ** **** ********* ****** ******** ******* ** production ********. ***** *** ****** ***** **** ** * ***-********** environment *** **** ** **** *** *** ******* **** ******* to ******** **** ** ************* *******.

Manufacturer ********

**** *** **** ** ************* **** *** ************* ********* *********** impacts **** *******. ** ***, ************* **** ********* **** *** still ** *** ******* ** *********** ******* *********** ******, *** recommended ********** *** ******** *******.

Comments (21)

**** ** *** **, ** ***** *** ******* / *****, you ******* *** **** * *********** ******* ** **** ***? Replace *** ***? ******* *** ******? **** *** ***'* ********* options?

** ** **** ** *** **** ******* **** ***** ******** so ***. ** **** *****, *** *** ** **** ** upgrade ** * ****** *********. *********, ********* ** ****** *** (if ********) *** **** ****.

***** *** ************* *** ***** **** ***** ******** ** ****, I ***** ***** *********** ** ********* **********, ** *******, ** much ** ********. ** ***** **** *** **** ****** ******** are *** **** ********* ******** *** ***** ********, ** *** would ****** **** ** ***** * ****** ***** ** **** CPU ** ****** *** ****** ************ **** **** *** ** processor ***********.

****, **** *** *** **** ********* ** ***, *** ** the ****** ** ********** ******** ************ (*.*.: *** ****** *** also ****** ******* ******, ***.), ** *** ** ****-********* ** off-load **** ************ ** ***** ******** ** **** ** *** for *** **** ***.

**** ********* **** ** *** **** *** ****** ** *** one ** **** ****** ***** ** * ****** ******* ** increase ********** *****. ********* ************* **** ******** *** ***'* *** uses *** *** ******** *****. *** *** *** **, ****

**** ********* **** **, *** **** *** ****** ** **** one ** **** ****** ***** **** **** ********* ******* ** offload *** ************* *****. **** ** *** *** *** **** mid-summer ** * *** ** * *** *** ***** ******** now, *** ** ***** ** ** * **** *** ********** low-cost ****** **** ** ****.

*** *** ***** ******** **** ** ***** ** * ****** environment **** ** * *** ******? ** *** ** ***** to ** ***** *** ** **** *** *** ** ****** random ****, ** ** * ******* *********?

************* **** *** **********'* ***** ** ****, ******** ******** *** not ** ****** ************ *******.

** *********** *** ******* ******* ******* ******** ******** ** ***** segments ** *** *******, *** ********* *** **** *** **** to *** ******** ** **** ****** *** ****** **********, ****** monitoring ** ********** ****** *****.

****** ** ****** **** **** ******* **** ** ******** ***** was **** **** ***********, ********** *** **** ** **-**% ** low ****** ***** ******* ***** ******** *** *****

******* ** *** ******* ************* *** ** * ************* **** right? *'* ****** **** ** ***** ** **** ** **'** at **% **** ** ** ******* ** **%-**%.

***, ****'* *******. *'** **** **** ** **'* **** *****.

***, *** **** ******* ** *********.

*** *******, *** ***** ****** ** *** *** ********** **** increased ** *% *** *****, ***** **** *% ***-***** ** 12% **** *****, **** *** * **% ********.

*** ******* ***** *** **** **** ******* ** ***** ******** code **** ** ******* * ****** *******. ****, **, *** Lenovo **** *** ******* *** ****** **** ******* **** ***** downloads *** *** ************ ****** *** ********* **** ** **** back. ** *** ******** ******* **** ****, *** ****** ** back *** ***** ** ** **** *** ****'* ******* * version **** *** **** *********.

**** *** ** ***** *****’* ******* ***** **** ****** ****

“** ********* **** ****, ***** ******* *********, ****** *************, ******** vendors *** *** ***** **** ********** ** ******* ********, ** they *** ********* ****** **** ******** ******* *** ***** ************* system ********,” ** *****.

*****://***.**********.***/*****-*******-*********-**-****-**********-***************-******/*******/******/

****** **** * ******* *********** **********, *** ******* **** **** Milestone ***** ****** ******** ************ *******? ** ***** ***** ** reason *** ***** *** ****** ***** ** **** **** **** if **** ***** ***** **** ** ****** *** ******...

****, ***** *** *** **** *********, **** **** **** ******** testing ****?

***'* ******* *** *** ***** ** *** ***** ******* *** retest ****?

***** *** **** * ***** *** ********** ******** **** ******** affects ******** ******* *** ***** ******** ********** ** ****. ** I'd ** ***** ******* ** **** *** *** **** *** Meltdown ***** ******* *** ***** ** *******.

** *** ********* ********** **** ********* *** ********** **** ********* whether ** *** ** ******** ******** *** **** *******.

*** ****** *** **** ** **** ** **** *** ********* to **** * ******. **** ** *** ********* **** ********** disconnected ******** *** **** *** **** **** ******* **** **** can ** ********* ** ***** ********, **** *** ********.

** ** **** ** **** ** **** ** *** ********* security ******* ** **** ** *** ****** ******* *** ********* actions.

**** ***** **** ******* ** *** ******, **** ** *** customers **** **** ** ** ********* *** **** ********* ******** if ***** ** ** *** ****** *** **** *******.

**** **** *************, *** ** ****** ********* ***** ** *********/***'* with ***** ***** ** **** *******/***** *******?

*** ***** *** ******** ************* ** ***** **** *******?

***** *** ********* ***************, ** **** *** ****** *** ** really.

***** *** ********* ** ********, ******** ******** *** **** * *** ******** ** ***** ** this.

*****,

**** **** * **** **** ******* ** ******* * **** smaller *** ** *** ***** *** ******** ** ****. **** this **** *** ********* ****** ** ******** ****/**** ** **** their ******** ****** ******* ****?

***, **** *** ***** *** ******** ****. ******** ********* ** the **** **** ** *** ***** *** ** **** ******** software/apps/etc., *** ******* ********** ******** ** ******** ******** ****** *** less ****** ** ** ********. * ****** ** ****** ***** that *** ** *** **** ****** **** ******, ***, ***, open ***** ** ******** ***** ****** * ****** ******** ** the ******.

********* ******** **** ** **** ********* ******** ***** ******** ** the ****** **** ** ******** ** ******** ***** ***************. (**** it *** *** *********** **** ** ** *********, ** ***** have **** **** *******-***** ***'*). **** **** ******** **** *** do *** **** * *** ** **** ****** ******** ** even ******* * *******, ** **** *** ***** **** **-***** systems ** **** ******.

**** **** ** **** *** ***** ** ***** ** ******* knowledge ** *** *************** *** ********. ** **** ******* ***** these *************** ********* ***** *****-*** ******* ***** ***** ** *** exploits ******* **** *** ******** **** ** ******* ****.

** ** ******* *** *************, **** ** * *** *****... sure **'* ******* ***, **** *** **** ******* ** ********* executing ** **** ****.

*** ******* ***** *** ** **** ** *** *** *** itself *** *** ********* *********** ** *** **** **** ***.

** ****** ****, ******* *** ******** * ******** ** **% performance */* ********* *****. **** ** ***** *** **** ***** with ******** *** ******* ****.

* ***** ** ********* ** ******.

******** **** ** *** (*********) *****'* **** ********/******* *** ********* on *** ***** ******* (****** **** ****** ** *** ****).

***** ** **** **** ******** (********.***.****.****.****.****) *** ****** *****.

*** **** **** **** ****** ***** ** ********://**************.*****.***/*****/***/********************.***

** ***** ********* *** **** ***** (*********)

*****://**************.*****.***/*******/*****/*****-***-***-*********

*** ****** **** ****** ** ***** ********* ****.

***** **** ***** ***** **** *** **** ******* ** ***** is *** **** ****** **** *** *******.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports on VMS

Cybersecurity for IP Video Surveillance Guide on May 18, 2018
Keeping surveillance networks secure can be a daunting task, but there are several methods that can greatly reduce risk, especially when used in...
Dahua 12MP Fisheye Camera Tested (NK8BR4) on May 16, 2018
Continuing our coverage of 12MP sensor fisheye cameras, we bought and tested the Dahua NK8BR4, examining: Default vs. Optimized...
Worst Manufacturer Technical Support 2018 on May 16, 2018
5 manufacturers stood out as providing the worst technical support to 190+ integrators in new IPVM results. These integrators answered: In the...
Axis 12MP Stereographic Camera Tested (M3058-LVE) on May 10, 2018
Axis has released the M3058-PLVE, a 12MP sensor, stereographic panoramic camera and Axis' first with integrated IR claiming images "sharp to the...
N3N "Truly Open Visualization Platform For Physical Security" Profile on May 09, 2018
A Cisco-backed startup, N3N, claims to deliver "the world’s first and only truly open visualization platform for physical security." The company...
S2 Access Control / 'Unified Security Management' Profile on May 08, 2018
In our 13th access control company profile, we examine S2 Security's Netbox platform: Unified Security Management Platform positioning Core...
Vivotek 12MP Fisheye Camera Tested (FE9391-EV) on May 08, 2018
Next in our 12MP fisheye camera evaluation, we bought and tested Vivotek's latest generation FE9391-EV, a new model claiming improved smart IR...
Hikvision VMD And Intrusion Analytics Tested on May 04, 2018
VMD worked poorly on Hikvision cameras, new IPVM testing found. However, Hikvision ships analytics on practically every IP camera, with intrusion...
JCI / Tyco VideoEdge NVR Profile on May 03, 2018
JCI (formerly Tyco) is one of the largest players in the global security industry, both as a manufacturer and an integrator. The company's most...
Avigilon 12MP Fisheye Camera Tested on May 03, 2018
12MP fisheye cameras have become mainstream, with nearly every major manufacturer offering their take on this segment. To see how these new higher...

Most Recent Industry Reports

Stealth / UCIT - Remote Video Monitoring Provider Profile on May 18, 2018
Can 2 remote video monitoring companies, Stealth Monitoring from the US and UCIT from Canada combine to impact the market and compete in a changing...
Cybersecurity for IP Video Surveillance Guide on May 18, 2018
Keeping surveillance networks secure can be a daunting task, but there are several methods that can greatly reduce risk, especially when used in...
Forced Entry / Duress Access Tutorial on May 17, 2018
Even though access control normally keeps people safe, tragedies have revealed a significant issue. If users are forced to unlock doors for...
ADT Stock Drops 50% Since IPO on May 17, 2018
It has been a brutal 4 months for ADT. They first expected to IPO at ~$18. They IPOed at $14, dropping immediately to $12.39 And now, not even...
Dahua 12MP Fisheye Camera Tested (NK8BR4) on May 16, 2018
Continuing our coverage of 12MP sensor fisheye cameras, we bought and tested the Dahua NK8BR4, examining: Default vs. Optimized...
Worst Manufacturer Technical Support 2018 on May 16, 2018
5 manufacturers stood out as providing the worst technical support to 190+ integrators in new IPVM results. These integrators answered: In the...
Installing Cameras in Plenums Tutorial on May 15, 2018
There is often confusion about plenum ceilings, with misinformation about what is required when running cables through them and mounting cameras...
Top Benefits Of Attending Trade Shows (Statistics) on May 15, 2018
150 integrators told IPVM: What are the top benefits of going to trade shows? The clear top 2 responses in order: (1) Networking (2) New...
Measuring For Security Installation Guide on May 15, 2018
Accurate measurement is a fundamental skill, yet many installers do not know how to do it. Using these tools are a key skill needed for security...
Arecont Files Ch.11, Agrees To Sell To Turnaround Specialist on May 14, 2018
The long-anticipated sale of Arecont Vision is finally happening. After raising $80 million in debt in 2014, a failed sale in 2017 and the...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact