Assessment of Windows Vista Kernel-Mode Security

Assessment of Windows Vista Kernel-Mode SecurityShort Description
enhancements in Windows Vista are quite substantial, resulting in a dramatic reduction of its overall attack surface. However, we …

Website: www.symantec.com | Filesize: 186kb

Content
SYMANTEC ADVANCED THREAT RESEARCH 1
Assessment of Windows Vista Kernel-Mode Security
Matthew Conover, Principal Security Researcher, Symantec Corporation
Abstract-Windows Vista introduces several additional barriers that aim to prevent malicious code from gaining access to the operating system kernel. This paper is intended to provide a technical review of their implementation. The kernel mode security enhancements in Windows Vista are quite substantial, resulting in a dramatic reduction of its overall attack surface. However, we have identified certain weaknesses in the kernel enhancements that may be leveraged by malicious code to undermine these improvements.
I. INTRODUCTION indows Vista introduces a number of security enhancements over prior versions of Microsoft Windows (including Windows XP SP2). The new kernel-mode security features in Windows Vista include among them: W
?Driver signing [1]
?PatchGuard [2]
?Kernel-mode code integrity checks [3]
?Optional support for Secure Bootup using a TPM hardware chip [4]
?Restricted user-mode access to DevicePhysicalMemory [5]
These changes may secure the kernel of Windows Vista 64-bit Edition significantly; even when compared to that of Linux or Mac OS X. The contributions of this paper are: (…

Get the file Download here

AddThis Social Bookmark Button
Related Books:
  • Analysis of the Windows Vista Security Model
  • Security Engineering in Windows Vista Blackhat 2006
  • Mac OS X Leopard Is a Joke Compared to Windows Vista
  • Hack Windows Vista in Reduced Functionality Mode
  • NUIT Tech Talk Preview Windows Vista OS
  • Configuration Guide UAH Wireless Windows Vista
  • Windows Vista Network Attack Surface Analysis A Broad Overview
  • Using Internet Explorer 7

  • Related Searches: , , , ,



    Comments

    Leave a Reply