帐号
密码
线路网通 电信 

个人观点:冯军 李易 文琪 吴海军 胡胜发 张峰 蓉晖 晋凯 陈富铭

  英文之窗 通路巨头  工厂 人物 数据 评论

中国3C消费求助社区 | 中国3C卖场报道 | 宠客网 | 中国网吧之家
独家 业界 产业 人物 评论 通路 顾问 披露 财经 采风 传闻 订单 内幕 报案 破案 会展 读书 观点 数据 人事 访谈 行情 促销 公告 企业
中国3C消费求助社区 中国3C卖场社区 内幕VIP社区 中国网吧之家社区 捷修网社区 易周刊 通路大哥大 宠客 华海3C卖场社区 分销价社区

McAfee:Vista或许是迄今为止最不安全的系统

 发表日期:2006-10-11 作者:George Heron 上下游撮合 分销价社区 内幕参考




Perspective: Why Microsoft is wrong on Vista security

For decades, and in every Windows operating system prior to Vista, Microsoft has relied on the contributions of third-party security vendors to help keep the user safe.

These products protected both consumers and corporate users from the ravages of malware such as viruses, spyware, trojans, worms and, most recently, rootkits.

These security products from independent software vendors even help keep people's computers safe from Microsoft's own critical software bugs, which notably have been on the increase in recent years.

Regrettably, Microsoft's own "buffer overflows" and "Internet Explorer exploits" have now become commonplace in today's lexicon. But again, the security products from the likes of McAfee, Symantec, Check Point Software Technologies, et al, have thankfully been available for people to choose in order to keep their computing experience safe.

Over the years, the users (i.e. you, me, our families and colleagues) have been able to select the best security solution for them from among any number of companies providing mature and innovative security products.

This cooperative and relatively safe computing experience is about to change for the worse in Vista.

Dropping down to the core of the operating system, we see that Microsoft has implemented PatchGuard as a means of preventing access to kernel services that classically have been allowed and available in all previous versions of Windows.

In a nutshell, PatchGuard crashes the computer when it detects that specific internal data structures have been "hooked," which is a common way that malicious software starts doing its damage.

However, the good advanced features of behavioral detecting and intrusion protection software also work this way. So by attempting to lock out the bad guys, PatchGuard is also blocking advanced security features from working, and the user is much less secure.

A straightforward example of this serious condition would be to consider the case of a new mass-mailing worm suddenly appearing in the wild. Typically, known viruses are caught during the delivery process, when the file containing the virus is scanned for the characteristic signature of the malicious software. If the bit pattern defining a known virus matches that in the incoming file, the file will be quarantined or deleted, according to the policy governing this on the computer.

A new virus, however, will not yet have a signature characteristic, as it has not yet been studied by the virus research team, so this zero-day attack will slip past the traditional antivirus checks in the kernel. Then, when the infected carrier file runs, and the virus ultimately then gets launched, it is born on the computer and immediately begins doing its dastardly deeds; in the case of it being a mass mailer, it ravages the e-mail client's address book and begins sending out tons of e-mails.

The cool part of the story next happens when the security software engages to stop the virus dead in its tracks. All modern antivirus software contains--in addition to the basic signature file scanning mentioned earlier--a technique termed heuristical behavior detection that is designed to stop a zero-day attack like the mass-mailer worm being described.

The calls being made by the worm into the kernel are studied by means of the antivirus hooking the APIs (application program interfaces), and it can be determined from the specific API calls and order/frequency of the calls that a worm is active in the system. The antivirus then kills the worm by issuing an Application Terminate call to the kernel, and the user is once again safe.

Of course, some other details are not depicted in this simple example. But the main point is that this is the way state-of-the-art antivirus operates today--to first detect the virus signature and in using behavioral techniques to detect the new, zero-day presence of new outbreaks. And the killer part of this example is that PatchGuard will prevent this type of behavior-based zero-day detection from operating.

The standard technique employed by security vendors for years and years--hooking the APIs and the ability of killing applications--is specifically being blocked. Further, Microsoft, which has no similar detection technique, is preventing security vendor antivirus packages from using these advanced features--even though Microsoft does not have the ability to do this itself.

The net-net is that the user is demonstrably less safe as compared to during the XP days, when security vendors could use their advanced behavioral features.

I'm not sure how we can end this story on a positive note. With Microsoft's design of Windows Security Center and PatchGuard, the restrictions on user choice of security solution, the stifling of innovation being forced upon the industry and, most of all, the clear and present danger of dramatically reduced user safety all comes to a head in Vista.

I suppose one can only hope that Microsoft can come to the realization at some point soon that the simple Vista alterations suggested by the industry must be taken seriously and implemented.


Biography
George Heron is McAfee's chief scientist.

 

·业者报料   ·渠道求助   ·消费者求助   ·网吧业主求助   ·在线报修

【声明】中国电子资讯参考刊载此文不代表同意其说法或描述,仅为提供更多信息,也不构成任何建议。对本文有任何异议,请联络question@discloser.net。


· McAfee:Vista或许是迄今为止最不安全的系统
· 微软:光学舒适鲨2000伴您走过健康、舒适之路
· 微软:向日本推出廉价Xbox360,抢占市场先机
· 微软:光学舒适鲨鼠标2000选择舒适、便携生活
· 微软:健康生活从使用光学舒适鲨1000鼠标开始

· 李焜耀认错:一开始,这就是一场不会赢的战役
· 通用电气:传将与EMC合作进军桌面显示器领域
· 明基:抛弃西门子挑衅社会责任,遗祸华人西进
· 尼葛洛庞帝:英特尔没有远见,如今抄袭我们!
· LG飞利浦:巨亏,第三季度可能亏3.358亿美元

 您的昵称: 
电 话:
 E-MAIL:   
职 业:
 评论显示选择:同意显示我的所有信息只同意显示我的名字


  

鉴于本站采用缓存技术的原因,您发表的评论将在1-5分钟之后才会显示,请耐心等待,不要重复留言。




请您注意:

1 、自觉遵守:爱国、守法、自律、真实、文明的原则.
2 、尊重网上道德,遵守《全国人大常委会关于维护互联网安全的决定》及中华人民共和国其他法律法规.
3 、严禁发表危害国家安全、破坏民族团结、破坏国家宗教政策、破坏社会稳定、侮辱、诽谤、淫秽等内容.
4 、承担一切因您的行为而直接或间接导致的民事或刑事法律责任.
5 、本站有权保留或删除或修改其管辖留言版中的任意内容.
6 、本贴提交者发言纯属个人意见,与本站立场无关.

 
·某平媒:通篇抄袭DI
·方正:品牌战线延伸
·明基:抛弃西门子挑
·联想:国庆前巩固“
·方正:国庆期间AMD新
·通用电气:传将与EM
·李焜耀:勇闯品牌孤
·渠道大焖锅:2006国
·三星:液晶存重大缺
·鸿海:总裁郭台铭个
·宏碁:绝版车神机现
·联想:国庆中秋,陈
·富士康:技嘉总代寻
·双敏:河南网吧采购
·海尔:涉嫌大忽悠,
·富士康:显卡节前全
·技嘉:传大陆板卡业
·双敏:挂羊头卖狗肉
·DELL:渠道凶猛,电
·美格:坦白显示器缺



集邦全球电子交易市集 王海热线 江苏商报 北京市消费者协会 中国3C消费求助社区 中国网吧之家 中国3C卖场报道
捷修网 中国计算机报 齐鲁晚报 宠客 北京晨报 南昌经济晚报 南昌日报 河南商报 西北IT网 雁塔在线 通路大哥大
中国家电网 荆门晚报 海峡消费报 南京电视台 湖北楚天广播电台 民主与法制时报 安徽商报 南京晨报 湖南电脑网 
联系我们 加入我们 设为首页 站内搜索 社区 博客
ICP证:苏ICP证040293 经营许可证:苏B2-20040174
Copyright © 1999 - 2006 中国电子资讯参考 All Rights Reserved