news4geeks.net
3Aug/120

Microsoft tool evaluates software’s impact on OS security

Microsoft has released Attack Surface Analyzer 1.0, a free tool that can help system administrators, IT security professionals, or software developers understand how newly installed applications can affect the security of a Windows OS.

The tool scans for classes of known security weaknesses that can be introduced by the files, registry keys, services, Microsoft ActiveX controls and other parameters created or changed by new applications.

It can identify executable files, directories, registry keys, or processes with weak access control lists (ACLs). It can also flag processes that don't mark memory regions as non-executable (NX), which could result in the bypassing of the Data Execution Prevention (DEP) Windows security feature. The tool also identifies services with fast restart times that could be attacked to bypass address space layout randomization (ASLR), as well as changes to the Windows Firewall rules or Internet Explorer security policies.


These and many other weaknesses that the tool identifies can facilitate various types of attacks, including some that could allow attackers to gain control of the system, execute malicious code or gain access to sensitive data.

The tool is already being used by internal product groups at Microsoft and a public beta version has been available to download since January 2011. The 1.0 stable version released on Thursday contains significant performance enhancements and bug fixes.

"Through improvements in the code, we were able to reduce the number of false positives and improve Graphic User Interface performance," the Microsoft Security Development Lifecycle (SDL) team said in a blog post. "This release also includes in-depth documentation and guidance to improve ease of use."

The tool has 32-bit and 62-bit versions and supports Windows Vista and newer versions of Microsoft's OS, including Windows 8 and Windows Server 2012 that hit the RTM (release to manufacturing) milestone on Tuesday.

Attack Surface Analyzer 1.0 is not compatible with the beta version of the tool, so existing users need to perform new "clean" system and post-application-installation scans -- known as the baseline and product scans respectively.

Attack Surface Analyzer requires .NET Framework 4 or higher present on the system in order to compare and analyze scan results. However, performing the actual scans can be done from the command line interface without .NET Framework.

(Source: infoworld.com)

 

In the midst of its latest campaign to fight piracy in China, Microsoft has signed an agreement with Lenovo to ensure that its PCs ship with licensed versions ...
READ MORE
Microsoft: Office 2013 license is for just one PC, FOREVER
Microsoft has clarified the licensing for retail versions of its Office 2013 productivity suite, confirming that boxed editions of the software are licensed for a single PC only ...
READ MORE
Despite threats to its software hegemony from Apple and others, Microsoft's stranglehold on enterprise IT has been its saving grace. Yet this advantage has started to fade as Apple and ...
READ MORE
Microsoft has licensed Lotus-to-anything migration software from Binary Tree, and plans to use its partner's wares to lure Lotus customers away from IBM and into the cloud. Kevin Allison, ...
READ MORE
Microsoft will allow users of Windows 8 Pro to downgrade their new PCs to Windows 7 or even Vista, according to the operating system's licensing agreement. Not surprisingly, users ...
READ MORE
Microsoft, Lenovo to promote genuine Windows on PCs
Microsoft: Office 2013 license is for just one
Windows 8: Never mind Office, it’s for GAMING
Office 365 turns Lotus eater
Microsoft will allow downgrades from Windows 8 to

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.