Error » Microsoft Error! » Microsoft Operating Systems Error » Microsoft windows vista error » Symantec Gives Vista Security a So-So Grade

Microsoft windows vista error all errors related to microsoft windows vista

Post New Thread Reply
  Symantec Gives Vista Security a So-So Grade
LinkBack Thread Tools Display Modes
Old 07-Mar-2007, 07:44 AM   #1 (permalink)
Administrator
 
Anilrgowda's Avatar

Posts: 18,720
Join Date: Jan 2006
Rep Power: 10 Anilrgowda is on a distinguished road

IM:
Default Symantec Gives Vista Security a So-So Grade

While Microsoft's Windows Vista operating system has made some big strides in the area of security, it doesn't fully protect users from emerging threats on the Web, security software giant Symantec concluded in a new report issued last week.
Symantec outlined its Vista security concerns in three papers released in July and August. While Symantec applauded some of the security work that Microsoft had undertaken in Vista (which was released in November), the security vendor raised legitimate concerns about the new technologies.
First, a quick summary of Symantec's 2006 reports. The first report urged caution over Windows' network stack, which was entirely rewritten with Vista and could give hackers new avenues of attack. The second concerned Vista's new User Account Protect (UAP) feature, which is designed to prevent users from automatically running with full privileges, and new "privilege isolation" techniques debuting with Vista. Lastly, Symantec took issue with steps Microsoft has taken to prevent malware from gaining kernel-level access by using digital certificates. It wouldn't be that hard, Symantec said at the time, for an illegitimate business person to get access to the certificates and sell them to malware writers.
In its report issued last week, titled "Security Implications of Windows Vista," Symantec looked at four main areas of Vista security, including generic exploit mitigation, kernel integrity, system integrity and user-mode defenses, and resistance to malicious code. It also looked at work Microsoft has done to Vista's network stack since last summer's beta releases. The security vendor maintained some of the original criticisms it leveled against the new operating system last summer, but said Microsoft has shown improvements in others.
Generic Exploits
Symantec lauded Microsoft's efforts on the topic of generic exploit mitigation. "The technologies introduced in Windows Vista are very effective at protecting the core Windows operating system as well as Microsoft compiled applications," Symantec says in the report, which is available for download here. "They serve to make the exploitation of traditional vulnerabilities infeasible, including those leveraged by well-known widespread worms observed earlier this decade. As a result, the overall impact of some code-level flaws, even when introduced by a Microsoft software engineer, is greatly diminished."
However, while the operating system has been greatly protected from exploits with Vista, older Microsoft products, as well as products from third-party developers, don't enjoy the same level of protection out-of-the-box. "Older Microsoft or third-party applications and drivers will continue to pose a risk, as they will remain largely unprotected," Symantec writes.
Kernel Integrity
Symantec was very critical of Microsoft on the topic of kernel integrity. While the company applauded the new technologies intended to protect the integrity of the operating system kernel (including driver signing, code integrity, and PatchGuard), Symantec says they don't go far enough, largely because they're only available in 64-bit versions of Windows.
The kernel-level protection technologies will only slow down, but not stop, hackers intent on breaking into the kernel, Symantec says. "Results have shown that all three technologies can be permanently disabled and removed from Windows Vista after approximately one man-week of effort," Symantec says. "A potential victim need make only one mistake to become infected by a threat that does the same. The result: All new security technologies are stripped from Windows Vista in their entirety."
System Integrity and User Mode Defenses
Symantec expressed some satisfaction with the new system integrity and user mode defenses in Windows Vista, most notably UAP. But it also found problems with these technologies, raising the possibility of attacks that take advantage of user fatigue related to the many UAP dialog boxes that Vista presents to users, and the possibility of attackers forging certificate and UAP dialogs themselves, leading to total system compromise.
A final and more worrisome issue is that users may ultimately disable these security functions, Symantec says. "While these types of risks may be easy to manage in the enterprise environment, managing them in a home environment may be nearly impossible," the company concludes.
Resistance to Malware
Symantec found Vista largely resistant to the range of viruses, worms, Trojans, keyloggers, and other assorted malware infesting the Internet today. The company found that only 3 percent of backdoors can successfully execute and survive a system restart on Windows Vista without modification, keyloggers 4 percent, mass mailers 4 percent, and only 2 percent of Trojans, spyware, and adware. It also found Vista was entirely resistant to rootkits, which it said it expected.
These are very low percentages, and make Vista very resistant to today's malware. However, Symantec found that, with only minor code changes to the malware, the percentage of malware that could install itself on Vista and survive a re-boot would "increase dramatically."
And this leads to Symantec's most dire warning to Microsoft: If hackers combined the known work-arounds to the new UAP feature, they could start turning out serious exploits that run at the highest authority level in Vista.
The company also had good and bad things to say about the new network stack. In the final release of Vista, Microsoft fixed three remote denial-of-service vulnerabilities and three historic network attacks that Symantec found in beta versions of Vista, "proving that Microsoft was making ongoing improvements to the Windows Vista network stack up until its final release. [However], it's highly likely that more will be discovered given the significant volume of new code," the company says.
In conclusion, Symantec says Vista's security improvements will continue to push hackers and malware writers away from the operating system and toward third-party applications, which is a trend that emerged with Windows XP Service Pack 2 (SP2). Vista users are still at risk today, only the vulnerabilities are being found in Web application technologies such as PHP, Python, Perl, ASP, and AJAX.
"Both enterprises and consumers will continue to face threats that Windows Vista and its built-in security features cannot protect against," Symantec says. "This is, in part, due to the slow pace at which operating systems can evolve in relation to today's ever-changing threat landscape."

Source:The Windows Observer--Symantec Gives Vista Security a So-So Grade
Anilrgowda is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 07:31 PM.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228