NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Windows

Windows


Attacking Vista from All Angles

Just testing...

By Marius Oiaga, Technology News Editor

28th of May 2007, 13:51 GMT

Adjust text size:


Windows Vista
Enlarge picture
Attacking Windows Vista from all possible angles is perhaps the best way to describe the testing process associated with the Secure Development Lifecycle. Microsoft feels secure enough on the infrastructure of the operating system that it is touting Windows Vista as the most secure Windows platform. A major contributor to this status quo is the SDL. According to James A. Whittaker, Microsoft Security Architect, the Redmond Company implemented a three-pronged strategy during security testing. The company assessed the security level of the application's
environment, the applications themselves and the adjacent functionality.

The relationship between environment and application is by no means predefined, on the contrary, it is subjected to variation. This is why during SDL testing, Microsoft has directed attacks at the components of the operating system, from the runtime libraries to the registry keys. "We train our testers to map out the environment, identify components subject to modification or variation and test as many configurations of these as possible. These attack scenarios are recognition that our applications work in unpredictable environments where we have to work out the trust relationships very carefully. It takes only one insecure component to put an entire machine or network at risk. We need to ensure that our own applications work securely despite the presence of these environment insecurities," Whittaker revealed.

Testing the application is synonymous with verifying program behavior when confronted with a range of malicious inputs. Microsoft tested Windows Vista against repeated exploits and targeted attacks. The testing scenarios involved a suite of known and documented malformed inputs. Windows Vista suffered intensive bombardment from malicious code, scripts, SQL queries, long strings and other such items. "Large scale automated testing comes into play here in a big way. Our goal is for our applications to be able withstand targeted and sustained attacks - whether it's a regression suite of past and potential exploits or fuzz testing using both random or format-aware logic," Whittaker explained.

Last but not least, Vista's functionality also came under scrutiny. The bottom line is that Microsoft ensured that it has bulletproofed the operating system against attacks designed to exploit its features. "We must look at our application's functionality and ask whether any of it can be 'turned against itself.' Are there ways that the software can be easily misconfigured?" Whittaker said. "Can security features be circumvented? Is there some function whose purpose is benign and even useful that under certain circumstances has undesirable consequences? A feature-by-feature assessment is necessary to ensure we've covered all the bases. "

TAGS:

Windows Vista | SDL
Read by 940 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.3/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Threw Windows Vista in a Pool of 1,400 Threat Models

Windows Vista Quality Tests

Scrubbing the Windows Vista Code Base

Microsoft Gathers Customer Data from Windows Vista

Mac Hacker: Windows Vista Is Superior to Mac OS X Tiger

Side by Side Comparison: Windows Vista Starter, Home Basic, Home Basic N, Home Premium, Business, Business N, Enterprise and Ultimate

Microsoft Is Getting Ready for Windows Vista Service Pack 1

Steve Ballmer Compares Windows Vista to Windows 95 and XP

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM