Microsoft adds security tools
Microsoft is looking to beef up security in the next version of Windows 2000 and, in the process, shed its reputation as poster child for the spread of malicious code.
Microsoft is adding controls to let administrators set policies that block the execution of downloaded code unless it is from a trusted source identified by corporate IT. The trusted sources are recognized as part of policies that are stored in Active Directory and automatically distributed to servers and desktops.
The company also is adding features to ease the rollout of certificates that help manage public-key infrastructure (PKI), a secure method for exchanging data. There also will be a new personal firewall in Windows XP, the next version of the desktop operating system.
IT executives are hoping the moves are a step toward more secure systems, but critics are calling them Band-Aids on a flawed architecture.
Windows XP and the next generation of Windows 2000 servers, code-named Whistler, will come with a policy engine called Software Restriction Policies that blocks mobile code from being executed by the user. Mobile code is executable code that is delivered to a desktop or server through the Internet or e-mail.
"I'm glad to see Microsoft acting instead of reacting," says Jeff Allred, manager of network services for the Duke University Cancer Center. Allred is keen on security issues because he is facing regulations under the Health Insurance Portability & Accountability Act of 1996, which sets standards for creating, storing and transferring medical-related data.
"I get a little comfort knowing controls like these are coming, because I will need them at some point," Allred says. But he also notes that he has dodged most of the problems because his mail system doesn't use Microsoft Outlook.
Outlook has been at the center of high-profile virus attacks in the past year. Those incidents have been a driving force behind another Microsoft push to show a dedication to security. This one is called "the war on hostile code."
But critics say the newest measures are a patchwork. "Anything they do in the security area around malicious code is just sticking something over the top of their systems so they don't bleed as quickly," says Frank Prince, an analyst for Forrester Research. Prince says the Office suite, which includes Outlook, has become its own distributed operating system, with executable code in the applications, but without the underlying security and management mechanisms of a true operating system.
Microsoft officials say that ensuring secure systems takes diligence in the product development process. "The challenge in the real world is to build software that is secure but that customers can buy and use," says Steve Lipner, manager of Microsoft's Security Response Center. "I don't think we have anything to apologize for, and we are committed to doing this well."
Microsoft internally is launching Secure Windows Initiative, which will bring specific training, tools, process controls and testing to the Windows Development Group.
» posted by ITworld staff
Network World
Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.
Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.
Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.
Crimeware: Understanding New Attacks and Defenses
By Markus Jakobsson, Zulfikar Ramzan
Published Apr 6, 2008 by Addison-Wesley Professional. Part of the Symantec Press series.
Enter now! | Official rules | Sample chapter
Securing VoIP Networks: Threats, Vulnerabilities, and Countermeasures
By Peter Thermos, Ari Takanen
Published Aug 1, 2007 by Addison-Wesley Professional.
Enter now! | Official rules | Sample chapter







