<a href="http://www.micropoll.com/akira/mpview/585320-168921">Click Here for Poll</a><a href="http://www.questionpro.com" title="online surveys">Online Survey</a><BR> | <a href="http://www.micropoll.com" title="Website Polls">Website Polls</a><BR> | <BR><a href="http://www.micropoll.com/akira/MicroPoll?mode=html&id=168921">View MicroPoll</A></div>

Visual Studio 2010!

Read now >

Windows Mobile Development Thoughts

Read now >

View Now
DevSource RSS FEEDS
XML Want an easy way to keep up with breaking tech news? And the Get DevSource headlines delivered to your desktop with RSS.
ADVERTISEMENT
ADVERTISEMENT

 

ADVERTISEMENT
Windows Vista Randomization Gets OEM Thumbs Up
By Ryan Naraine

Rate This Article: Add This Article To:

Microsoft's use of code-scrambling diversity in Windows Vista has received a major thumbs up from U.S. OEM partners.

Microsoft's use of code-scrambling diversity to secure Windows Vista is getting crucial support from OEM partners.

The Redmond, Wash. software giant has convinced major U.S. computer makers—including Dell, Gateway and Hewlett-Packard—to make default changes at the BIOS level to allow a new Vista security feature called ASLR (Address Space Layout Randomization) to work properly.

ASLR, which is used to randomly arrange the positions of key data areas to block hackers from predicting target addresses, is meant to make Windows Vista more resilient to virus and worm attacks.

However, for randomization to be effective, DEP/NX (Data Execution Prevention/No eXecute) must be enabled by default.

During a three-day conference to in November 2006, Microsoft security program manager Michael Howard said he pleaded with OEMs to enable DEP/NX in the BIOS by default on all their shipping PCs in time for Windows Vista.

Howard, a key evangelist for Microsoft's SDL (Security Development Lifecycle) process, used his personal blog to announce that all the major OEMs "have agreed to not disable DEP/NX in their BIOSes by default."

"This is huge," Howard declared.

Because most CPUs that ship today support DEP/NX, Howard explained that Vista users on older hardware can use the control panel to manually verify that PCs have DEP enabled.

With full support from OEMs, Microsoft is effectively using ASLR to create software diversity within a single operating system, a move that is widely seen as Redmond's attempt to address the monoculture risk.

The memory-space randomization technique will block the majority of buffer overflow tricks used in about two-thirds of all worm and virus attacks.

When used in conjunction with other technologies, Microsoft believes ASLR can provide a "useful defense" against malware attacks.

Beyond ASLR, Windows Vista has been fitted with /GS to detect some buffer overruns, a compile-time option in Visual C++ that adds stack-based buffer overrun detection, /SafeSEH, DEP and Function Pointer Obfuscation as technologies that help to lock down the operating system.

Windows Vista also introduces Windows Service Hardening, kernel patch protection, mandatory driver signing, User Account Controls, a new log-on architecture, network access protection, easier smart card deployments and various technologies to protect against malware and hacker intrusions.

Check out eWEEK.com's Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at Ryan Naraine's eWEEK Security Watch blog.




Discuss Windows Vista Randomization Gets OEM Thumbs Up
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Microsoft Architecture Articles          >>> More By Ryan Naraine