Skip Links

Network World

  • Social Web 
  • Email 
  • Close

PatchGuard and Windows security circus

By Daniel Blum , Network World , 11/24/2006
Blum
  • Share/Email
  • Comment
  • Print

Here's a metaphor for the future of Windows security: Microsoft and the industry are two acrobats on a tightrope with no net. The trick is to meet in the middle, shake hands and maneuver around each other.

PatchGuard, a feature that causes 64-bit Windows versions of Vista to blue-screen if the kernel code is modified unexpectedly, is the first of possibly many flashpoints as Microsoft adds new security features to its product line. Also called kernel patch protection, PatchGuard may stop some attack programs from infecting a system by embedding themselves in the kernel. However, PatchGuard also gets in the way of security vendors that "hook the kernel" to ensure their routines are called at the right times to monitor the system for unauthorized activity.

At first glance, PatchGuard seems like a desirable feature. It doesn't cost anything, and none of us wants malware messing with our kernels. Nor does hooking the kernel do much for system stability. Unfortunately, vulnerability researchers have demonstrated PatchGuard isn't a silver bullet and Vista isn't bulletproof. Much as we don't want to pay security taxes to independent software vendors (ISV), we still need them.

Microsoft must protect the operating system, but it should not deny customers a choice of security products. And given that Microsoft is competing with ISVs by selling its own Live OneCare antivirus package, it would be difficult for the company to be completely even-handed with PatchGuard, Windows Security Center and all the features that integrate security with the operating system.

Fortunately, European Union regulators assumed an oversight role, demanding even-handedness to protect customer choice. Bowing to the inevitable, Microsoft has initiated talks on PatchGuard with ISVs and now says 95% of ISV requirements boil down to three issues: monitoring/controlling process and thread launching; protecting the ISVs' programs from malware; and monitoring/controlling cross-process memory manipulation.

Microsoft says it is working to complete a new design in 90 days and will ship new application program interfaces (API) for security ISVs with Vista Service Pack 1. With these APIs, most host intrusion-prevention systems and other types of products should be able to protect systems without having to hook the kernel.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed