Free Newsletters




   
CIO magazine chief information officer ERP IT strategy  research  analysis business technology e-business CRM customer relationship management e-business   enterprise resource management leadership
CIO.com
About
Search
Awards Programs
Subscribe
Magazine
Current
Previous
Print Links
Newsletters
CIO Store
CIO Conferences
CIO Executive Council
Blogs
News Alerts
CEO Reading
IT Strategy
Tech Linkletter
Tech Policy
Viewpoints
Experts
Alarmed
Analyst Corner
Beneath the Buzz
Consultant Briefing
Higher Learning
In the Know
Leading Questions
Weigh-In
Discussion Forums
Career
CIO Wanted
Counselor
IT Events Calendar
Movers & Shakers
Research & Polls
CIO Research Rpts
Quick Poll
Tech Poll
Reports & Guides
CIO Bookmark
Reading Room
Special Reports
Compliance
RITLAB
State of the CIO
Webcasts
White Papers
About Us
Advertise at CIO
Conference Info
Editorial Calendar
Editorial Staff
List Services
News Bureau
Reprints
Sales
Related Sites
CSO
CMO
Darwin
IDG Network
Feedback to CIO
© CXO Media Inc.
subscribe to CIO Magazine



Home > CIO Metrics
Regulatory Resource   Threat Intelligence      Resilient IT      Boardroom Strategies      
Threat Intelligence / Preparedness

Solid Windows Vista Protection

By Tom Schmidt

It goes without saying that attackers follow security vulnerabilities, as these are a requirement for their success. Over the past several years, these vulnerabilities have increasingly moved up the application stack and away from the core operating system. Threats have moved (and will continue to move) into other areas, such as the Web application layer, where the majority of all new security vulnerabilities reside today. These threats target more available technologies, including email, IM, and the Web, leveraging social engineering and other convincing trickery in order to infect their victims.

That said, the release of an operating system that is expected to be widely adopted -- such as Microsoft's Windows Vista -- is bound to have a significant effect on the security landscape.

Over the past year, security researchers have examined potential security issues associated with the new Microsoft operating system. This article will discuss the findings of that research and describe why the implementation of a multi-layered security strategy on top of Windows Vista is critical.

Threats Becoming Evident
The security issues pertaining to Windows Vista fall into three categories: vulnerabilities, malicious code, and attacks against a specific protocol.

In December 2006, researchers reported a vulnerability in previous versions of Windows that also affects the version of Windows Vista that was released to consumers in January. No matter how mature development processes such as Microsoft's Security Development Lifecycle (SDL) are, Vista is a complex system and, as already shown, not immune to flaws and human mistakes.

In April, Microsoft patched the already exploited Windows animated cursor vulnerability with an out-of-cycle security update. The security bulletin rated the bug as critical -- Microsoft's highest threat level in its four-step system -- across all supported editions of Windows: 2000, XP SP2, Windows Server 2003, and Vista. The vulnerability marked the first critical Vista bug disclosed and patched since the operating system's release, and the first flaw in Vista's own code.

As for existing malicious code, it too may pose a problem for Windows Vista. According to research, some malicious code that did not originally target Windows Vista may affect the new operating system after all. This could be problematic because some enterprises may act on the belief that their installations of Windows Vista are immune from older malicious code samples. As a result, they may not deploy appropriate security solutions on new Windows Vista systems, thus leaving them vulnerable to infection by older malicious code samples.

For example, late last year, an analysis of Windows Vista's security enhancements was conducted provided by the user account control (UAC) and resulting new security barriers. Approximately 2,000 unique instances of malicious code were executed during the life of this project.

On average, about 70% of the malicious code executed under Windows Vista loaded successfully and executed without a crash or runtime error. Out of the 70% that were able to execute, only about 6% of the samples were able to accomplish a full compromise and an even smaller number (4%) were able to survive a reboot. The rest did not execute properly due to incompatibility, unhandled exceptions, or security restrictions.

The implementation of malicious code on Windows Vista will change. Malicious code authors will no longer target the system as a whole, but will be forced to target the user environment to accomplish what they want. Needless to say, the possibilities for infection are still endless. Malicious code can continue to survive on Windows Vista with relatively minor changes. The possibility of an existing threat successfully executing, infecting, and surviving on Vista is still a concern.

The third potential Windows Vista security issue is the Teredo protocol. Teredo was developed by Microsoft to enable the transition between versions of Internet protocol (IP), one of the protocols underlying all Internet-based communications. Teredo is enabled by default in Windows Vista, and computers using Windows Vista can easily be identified through Teredo. Attacks sent over Teredo will often bypass organizations' network security controls. Many security products don't support Teredo and thus would not inspect it. This could make Windows Vista susceptible to attacks through Teredo.

Attackers Shift Their Focus
As every IT professional knows, attackers follow security vulnerabilities, as these are a requirement for their success. Over the past several years, these vulnerabilities have increasingly moved away from the core operating system. Threats have moved -- and will continue to move -- into other areas, such as the Web application layer, where 66% of all new security vulnerabilities reside today. Windows Vista provides no enhanced security in this space, as the majority of vulnerabilities today are seen within PHP, Python, Perl, ASP, and other languages. In addition, new Web 2.0 technologies such as AJAX provide an entirely new layer on which tomorrow's threats will propagate.

A Multi-Layered Defense
For organizations that are pondering a Vista migration, integration is a critical aspect of any client security solution. Antivirus and antispyware protection, vulnerability-based protection, file-based intrusion prevention, and firewall traffic control components of a security solution all need to be able to communicate with each other and work together to protect the client system. Lack of integration between solutions often requires manual intervention, weakening the ability to adequately combat threats. Only through a coordinated, multi-layered defense can an organization effectively protect itself against the rising barrage of crimeware and threats to Windows Vista.

In addition to providing a coordinated defense, an integrated client security solution can be more easily managed than individual point products. Integration allows for centralized management from a single console rather than multiple consoles. IT administrators only have to learn and use one console instead of four. Additionally, instead of having piecemeal reports that leave gaps in the client security picture, they can run a single report to get either a comprehensive or snapshot view of the entire state of their client security, letting them easily see their weaknesses and strengths. This overall ease of management that an integrated client security solution provides greatly simplifies administration efforts and frees up IT personnel to pursue activities that drive business success and improve the organization's bottom line.

Conclusion
As with any new operating system, Windows Vista's release will bring with it previously unforeseen security issues that IT managers will need to grapple with. Vista's new features and changes to Windows Vista's code base, in conjunction with increased scrutiny from security researchers and malicious code authors, will result in previously unseen attacks.

Vista undoubtedly will be a boon for businesses and users alike, but its arrival also means that there will be yet one more operating system that IT managers will need to manage and secure. The new security features included in Vista are a step forward in helping businesses defend against attacks, but they cannot be considered a complete, multi-layered defense.

The advanced state of malware development will continue to require dedicated countermeasures, and organizations will need ways to manage and secure multiple platforms. In short, Vista is an important step forward, but the new operating system is only the first step in ensuring the security of an organization's computing resources.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

CIO Strategy Center is a daily editorial resource offering innovative insights and strategies for building an integrated, secure and resilient IT infrastructure.

Articles by Topic
Spam and Viruses
Preparedness
Strategies
Related Content
Fast Fact

For organizations that are pondering a Vista migration, integration is a critical aspect of any client security solution.

Sponsor Tools
Podcast Audio Content

CIO Strategy Center is now available in audio format.

This week's feature topic is:


Risks of Wireless Email
Playtime: 8 min 23 sec



Download | Subscribe







Advertisers



Free Newsletters
Sponsor Content
 Domains
Compliance CIO Partner Domain for I.T. Productivity
The domain for everything you need to assess, measure and improve
IT Productivity within your organization, Whitepapers, Books, Research, Benchmarking tools and lots more.
 Webcasts
Compliance Failure is not an option: Why online compliance and security can’t wait.
Compliance BI Standardization: Attend our virtual conference for real advice.
Compliance Getting Smart about Offshoring: How Visual Simulation Gets It Right the First Time
Compliance Turning Best Practices to Best Projects
Compliance Securing Enterprise Data In An Unsecured World
Compliance A New Game—The Fast Emerging World of IP Convergence
Compliance All CIO Webcasts
 White Papers
Compliance Organizations Shift Focus to Information Management
Compliance Tera-Scale Data Warehouse Appliances Overcome the Technology Bottleneck
Compliance Knowing the Risk
Compliance Why Asset Management and Discovery are Core Contributors to Effective Business Service Management
Compliance Start your ERP upgrade with a distinctive master data advantage
Compliance Putting your Spend Data Warehouse on steroids
Compliance All CIO White Papers

IDG ENTERPRISE NETWORK

NetApp launches expanded NAS line - Infoworld Staff
IBM, BEA lay out new Java specs - Infoworld Staff
  »More  

Phishing scams rocket
Wi-Fi switches: breakthrough year, future fear
  »More  

Users get going on SP2 rollouts
Shark Tank: Just one more thing to remodel
  »More  

SPONSORED LINKS:
Align IT with business goals. Introducing PlanView Enterprise.
A data warehouse 10-50x faster at ½ the cost. Learn more!
How do you compare with 565 IT organizations?
For real advice on BI Standardization attend the Virtual Conference on Feb 22
Manage IT Change. Manage the Business. Free white paper.
Ten Principles for Knowledge Management Success" - Get the free white paper from ServiceWare
Audit the Data or Else: Un-audited data increases business risk Grid
See Qualcomm, EPL, and Deutsche Post on the Oracle Grid
Preventing Client/Vendor Mismatch: click here to learn more

Free Newsletters

Dated: March 01, 2005
http://www.cio.com/blog_view.html?ID=221


About CIO.com | Welcome | Privacy Policy | Terms of Service | Linking to us

CIO.COM complies with the ASME Guidelines with IDG extensions for new media.

CIO magazine chief information officer ERP strategy IT research analysis business technology management e-business knowledge management intranet CRM cio.com CRM customer relationship management e-business ERP enterprise resource management leadership management measuring IT value outsourcing supply chain

© 1994 - 2005 CXO Media Inc.

An International Data Group (IDG) Company



 HOME  CURRENT ISSUE  ARCHIVE   About CIO :: Advertise :: Subscribe :: Conferences 

Reprints, IDG Network, Privacy Policy

THE IDG NETWORK
CSO :: CMO :: Darwin :: Computerworld :: Network World :: Infoworld :: PC World :: Bio-IT World
IT Careers:: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp



Problems/complaints/compliments about this site can be sent to deiben@cio.com.