
64-bit Windows Vista PatchGuard technology has created a lot of complaints, a lot of noise a lot of confusion. This affirmation belongs to Richard Jacobs, Sophos Chief Technical Officer, and
is directed at Symantec and McAfee. In a podcast available on Sophos's Website, Jacobs answers the question: "Is Microsoft stopping your security vendor from doing their job?"
And the answer is yes. Yes, Microsoft does prevent your security vendor from doing their job. But there are nuances associated with this yes answer. And it all comes down to 64-bit Windows Vista PatchGuard or Kernel Patch Protection. In fact PatchGuard, introduced in 64-bit Windows Server 2003 and in 64-bit XP SP 2005, it kills certain technology from Symantec and McAfee, the behavior-based security technology.
This happens because the behavior-based technology uses the same modus operandi as the malicious code: hacking and patching the operating system's kernel. Symantec too has accused the Redmond Company of killing behavior-based security technology on the 64-bit edition Vista.
PatchGuard renders pro-active protection solution Host Intrusion Prevention useless. But is the fact that the Kernel Patch Protection blocks real time behavior-based threat detection an example of Microsoft foul play as Symantec and McAfee have implied? Jacobs' answer is no. Furthermore, he welcomes the technology as behavior-based solutions involve patching the kernel of the operating system and then monitoring the behavior on the machine to identify potential threats after their execution and only then attempt to clean them up. In fact, Jacobs' conclusion is that PatchGuard is a legitimate security solution while HIPS is not.