300 likes | 439 Views
Windows Security. Myles Maxfield John Smith Rick Born. Old School. IBM/MS DOS. 1981 – purchased by Micro-soft Single user, Limited network support No user security No File security. Windows 3.1. Added Protected_Mode Task Switching only
E N D
Windows Security Myles Maxfield John Smith Rick Born
IBM/MS DOS • 1981 – purchased by Micro-soft • Single user, • Limited network support • No user security • No File security
Windows 3.1 • Added Protected_Mode • Task Switching only • Added some virtual capabilities of the 386 processoe if run in 386 Enhanced mode
Windows 95 • Built in TCP/IP stack • 32bit operating system • Appears to be multiuser
Windows 98/ME • Built in browser (IE)
References • http://www.nukesoft.co.uk/msdos/dosversions.shtml • http://www.lbl.gov/ITSD/Security/systems/win-checklist.html
What is Windows NT? • Windows meant for business and server usage • Multiprocessing and multiuser support was important • The basis for modern Windows releases
Security Model • Security Descriptors (SD) • Access Control Lists (ACL)
Security Descriptors • Every single anything on NT has one. • It IDs the owner of the thing and has an ACL attached
Access Control Lists • A list of all of the user and groups and their permissions on the object • Contain Access Control Entries, which specify access for individuals • Two Types • Discretionary: Controlled by the owner • System: Controlled by system administrator
Access Token • Used to id a user and their groups for use with SDs.
Pre-2000 are Broken! • A flaw in early versions of NT are vulnerable to DoS attacks through RCP. • Not patched in pre-2000! • The underlying system would need to be changed too much
References • http://www.microsoft.com/technet/security/Bulletin/MS03-010.mspx • http://msdn.microsoft.com/en-us/library/ms995339.aspx • http://msdn.microsoft.com/en-us/library/ms995341.aspx
Windows XPWindows Vista Securitah!
Most Popular • 60-90 Percent market share • Most targeted • Windows Update lag
Service Packs • Service Pack 1 • Patches and hotfixes • Service Pack 2 • Data Execution Prevention • Security Center • Service Pack 3 • .NET patches
Security Center • Firewall • Automatic Updates • Antivirus • Note: Unix
User Access • Default operating as Administrator
Similar to XP • Security Center* • Data Execution Prevention
Security Center • Vanilla Installation • Firewall • Automatic Updates • Malware Protection • Internet Security Settings
User Access Control • Problem with XP • Authentication • User and Administrator at the same time • Annoying
Windows Defender • Problem with XP • Malware security
Address Space Layout Randomization • OpenBSD
Digital Rights Management • Non effective