Assessment of Windows Vista Kernel-Mode Security
Short Description
enhancements in Windows Vista are quite substantial, resulting in a dramatic reduction of its overall attack surface. However, we …
Website: www.symantec.com | Filesize: 186kb
Content
SYMANTEC ADVANCED THREAT RESEARCH 1
Assessment of Windows Vista Kernel-Mode Security
Matthew Conover, Principal Security Researcher, Symantec Corporation
Abstract-Windows Vista introduces several additional barriers that aim to prevent malicious code from gaining access to the operating system kernel. This paper is intended to provide a technical review of their implementation. The kernel mode security enhancements in Windows Vista are quite substantial, resulting in a dramatic reduction of its overall attack surface. However, we have identified certain weaknesses in the kernel enhancements that may be leveraged by malicious code to undermine these improvements.
I. INTRODUCTION indows Vista introduces a number of security enhancements over prior versions of Microsoft Windows (including Windows XP SP2). The new kernel-mode security features in Windows Vista include among them: W
?Driver signing [1]
?PatchGuard [2]
?Kernel-mode code integrity checks [3]
?Optional support for Secure Bootup using a TPM hardware chip [4]
?Restricted user-mode access to DevicePhysicalMemory [5]
These changes may secure the kernel of Windows Vista 64-bit Edition significantly; even when compared to that of Linux or Mac OS X. The contributions of this paper are: (…
Get the file Download here
Related Books:Related Searches: kernel enhancements, kernel mode, integrity checks, indows vista, security enhancements
Comments
Leave a Reply