New Security Feautures of Windows Vista in System and Kernel Mode
New Security Feautures of Windows Vista in System and Kernel Mode
Section 1: Security Development Lifecycle
The Security Development Lifecycle technique or SDL is a professional process that helps for making sure that the software are built from the
base to reduce security risk. The SDL implements a professional process of secure design, coding, implementing, testing, review and response for all Microsoft products specific windows Vista .The SDL removes the surface area for attacks, improves operating system and
application be bugless, and helps organizations high securely management and isolate the network.
We can say that The Windows Vista is the first client operating system to be Designed and developed from the first step to finish using SDL.More than 1,000 threat models were developed for Windows Vista to ensure identification and reduse of risks in different parts of the
operating system that required especial testing.
Section 2: Kernel Patch
The most important security issue is out “operating system kernel”. These rootkits are usually very useful for unwanted software, like
spywares. Kernel patch Protection of rootkits can reduce the Risk and increase stability, reliability and performance in the system, include All User data and programs.
Handling of these problems were very difficult before, because 32-bit Windows drivers like windows XP are not identified and compatible
with digital signature and It has Unsupported and poor kernel.Windows 32-bit security products that provide blocking action capabilities modify the kernel through unsupported techniques .
Although the computer system moves from 32-bit to a 64-bit architecture but the smaller installed base of 64-bit software makes it
possible to making significant enhancements for security in the kernel and reduce the potential for rootkits .
What is Kernel Patching?
Kernel patching is the practice or trying for using unsupported methods or features to change or replace of kernel code. Kernel patching can
have different result in behavior during system instability and performance errors and problems such as the Blue Screen error that we know it can reach to lost user data. another issue that is very important in kernel patching is increase the mechanism versus malware developers and attackers for Windows Vista Operating system.
The biggest risk in kernel patching is about virus and spyware writers that use this technique with malicious for hiding their presence and
effects.
Of course Malware authors are motivated for patching the kernel because That’s a powerful and great mechanism for attacking the computers and data. What is Kernel Patch Protection?
There are many features of security in Windows Vista. But I want to emphasize Kernel Patch Protection is not one of them. I mean Kernel
Patch Protection created in x64 CPU architecture versions and Microsoft used it in Microsoft Windows Server 2003 SP1 and Windows XP Professional. but it not supported in x86 architectures or 32-bit systems. With increasing of using of 64-bit computers, The
Vista users will see more benefit from this technology. Actually Kernel Patch Protection monitors and looks if any resources used by the kernel or probably kernel code has been changed or modified by itself. Fortunately If windows vista detects or feels any unauthorized patch of data or code it will shut down the system
automatically. But we should consider that the Kernel Patch Protection can not prevent all viruses and malware . It can prevent one way versus attackers to system.
Section 3: Encrypting File System improvement:
We can say that The Encrypting File System or EFS is best tool for encryption of files in client and server computer. It helps users to protect their data from Unreal and unauthorized access by other person or computer or external attackers. In Windows Vista EFS includes many new security techniques and features.In Vista, EFS Technique supports “user keys storing” and also administrative keys on the smart cards. If smart card uses for login, EFS will operates in a Sign On mode, where it uses the login smart card for file encryption without require for the PIN. In windows vista through the process of creating and setting smart card keys performs their files from an old smart card to the new smart card . The utility program for smart card has these features as well.
EFS is available in Windows Vista Business, Enterprise and Ultimate.
Section 4: USB Device and Removable Devices Control:
As we know , connecting between Devices with computer is very usual in these days and users should have the ability to add new hardware to
the computer or use USB Devices or another removable storage devices.It can create two problems in system: First it may make harder
to maintain the computer when we install any unsupported device, and second it can create threats to data security as well. with a USB
Device or removable storage, with “autorun” technique can use by an attacker to install malwares or any malicious software on an
unattended system.
Fortunately Windows Vista manages or blocks the installation of unsupported or unauthorized parts or devices. These security configuration can applied independently on a client computer, or in
numbers of systems in a network. Administrator has a lot of power for setting these policies and controls in Windows vista. We can say that
The Group Policy settings are available special for manage and control for reading and writing action in removable storage devices like USB
Devices as a per user or per system base.
Section 5 : Windows Defender
As we know in these years spyware and other unwanted software like adware, bots and rootkits create big problems for systems and users.The progress of job for these type of software is Usually they installed without a user’s knowledge or confirmation and they can damage or corrupt personal information and passwords and send them
to third parties without the user’s permission.
Microsoft Knows that it is very important for users to use anti-spyware protection in system. As customer choice, Microsoft supports users for
having choice about what program install and run on their computer or from where it came or what it does and how we can to remove that.Based on these discuses and users complains about spyware, Microsoft decided to create and use anti-spyware solution or Windows Defender in Windows Vista. In fact Windows Defender will help for protection
and remove spywares, adwares, rootkits, control utilities and such these things that we call “malware.” In Windows Vista, Windows Defender helps us for protection of unwanted application and software installation. It prompts and monitors different aspects of OS when feels it abused by malware , like the Startup folder in windows and the registry file. If any software to
attempt for changing to one of the protected areas of the Vista , Windows Defender prompts and appeara a message the user for allow or reject that changes.Good news , Windows Defender is available as a free download plug ins for licensed customers of Windows 2000, Windows XP and Windows Server 2003.
Section 6 : Windows Firewall
Most of Windows XP users used from Firewall. A firewall is a critical first line for defense versus huge kinds of malware before they can
enter to user’s computer or our network.
When Microsoft XP released in the first version of that the built-in firewall be turned off by default. The reason was because of compatibility with some applications or probably third-party firewalls. Based on that Microsoft released the Windows XP with the disabled
firewall by default. Naturally , a lot of customers and users did not get any benefit from firewall protection whenever any network worms
arrived to their computer.
Windows Vista Firewall
Base on this experience and for prevent of such events, naturally the firewall in Windows Vista should be on as a default and also compatible with another software. because of that the Customers who want to use a third-party firewall can turn off the built-in firewall easily.
It means the firewall in Windows Vista will turn on by default at the beginning when Windows starts for user protection. Another issue is
that The Windows Firewall in Windows Vista also allows the administrator of network or single system to block some applications as a peer-to-peer sharing softwares or instant messaging softwares that usually nobody like them.
Section
7: Protecting the Kernel of Windows in 32-Bit vs. 64-Bit
Microsoft as a designer and developer of Windows vista tried the best for create more reliable and more secure product from attacks. In fact in basic level, It means that the design and development of kernel mode code in Windows Vista
needs to have a security-focused design and development, and then test and release. As I Mentioned Microsoft has been started this Method since 2002 Under Security Development Lifecycle (SDL) progress. The Microsoft development team had an important and clear goal for improving the reliability and security in new product . As a producer It has a risk because of application
compatibility should considered in during security platform. In 32-bit
