280 likes | 432 Views
Security Features in Windows Vista. Chalermrath Kongkangwanchoke Technology Specialist |Core Infrastructure Platform Identity and Access Management | Security | Networking. What Will We Cover?. Security fundamentals Protecting your company’s resources Anti-malware features.
E N D
Security Features in Windows Vista Chalermrath Kongkangwanchoke Technology Specialist |Core Infrastructure Platform Identity and Access Management | Security | Networking
What Will We Cover? • Security fundamentals • Protecting your company’s resources • Anti-malware features
Helpful Experience • Windows user interface • Windows security concepts Level 200
Agenda • Exploring Security Fundamentals • Mitigating Threats and Vulnerabilities • Controlling Identity and Access • Protecting System Information
Windows Vista Fundamentals Secure by Default • Improved SDL • Common Criteria Certification
Windows Vista Service Hardening D D D D Kernel drivers User-mode drivers D D D D • Reduce size of high-risk layers • Segment the services • Increase number of layers Service … Service 1 Service… Service 2 Service A Service 3 Service B
Agenda • Exploring Security Fundamentals • Mitigating Threats and Vulnerabilities • Controlling Identity and Access • Protecting System Information
Internet Explorer 7.0 Social Engineering Protections Protection from Exploits • Unified URL parsing • Code quality improvements (SDLC) • ActiveX opt-in • Protected Mode to prevent malicious software • Phishing filter and colored address bar • Dangerous Settings notification • Secure defaults for IDN
Advanced Malware Protection Admin-Rights Access Install a driver and run Windows Update Change settings, save a picture Install an ActiveX control Redirected settings & files HKLM Program Files IEUser IEAdmin IE6 Exploit can install malware Exploit can install malware User-Rights Access Integrity Control Internet Explorer HKCU My Documents Startup Folder Compact Redirector Change settings, download a picture Temp Internet Files Un-trusted files and settings Cache Web content
ActiveX Opt-in IE7 blocks ActiveX Control User grants permission (opts-in) IE7 ActiveX Control enabled Disabled Controls by default IE7 confirms install
Windows Vista Firewall IPSec
demonstration Demo • Configuring the Windows Firewall • Configure Computer Connection Security • Configure an Inbound Exception
Windows Defender Improved detection and removal Redesigned and simplified user interface Protection for all users
Network Access Protection Fix Up Servers Policy Servers Windows Vista Client DHCP, VPN Switch/Router MSFT Network Policy Server Corporate Network
Agenda • Exploring Security Fundamentals • Mitigating Threats and Vulnerabilities • Controlling Identity and Access • Protecting System Information
User Account Control Allows system to run as standard user Allows select applications to run in elevated context Fix or remove inappropriate administrative checks Registry and file virtualization provides compatibility
demonstration Demo • Reviewing User Account Control • Use Windows Vista as a Standard User • Customize User Account Control
Integrated Control Control over removable device installation Restart Manager Security Center enhancements
demonstration Demo • Blocking Unauthorized Devices • Block the Installation of a USB Flash Drive
Agenda • Exploring Security Fundamentals • Mitigating Threats and Vulnerabilities • Controlling Identity and Access • Protecting System Information
Windows Vista Data Protection Policy Definition and Enforcement Rights Management Services User-Based File System Encryption Encrypted File System Drive-Level Encryption BitLocker Drive Encryption
BitLocker Drive Encryption • Improved at-rest data protection with full drive encryption • Usability with scalable security protections • Enterprise-ready deployment capabilities • Offline system-tampering resistance • Worry-free hardware repurposing and decommissioning • Integrated disaster recovery features
Trusted Platform Module Encrypted Volume Key Encrypted Data Encrypted Full Volume Encryption Key Cleartext Data TPM Volume Master Key Full Volume Encryption Key
Spectrum of Protection ******* Ease of Use TPM Only Dongle Only TPM & PIN TPM & Dongle Security
Session Summary • Windows Vista is the most secure Windows operating system to date • Windows Vista protects users • Numerous other security improvements help protect data and ease deployment
For More Information Windows Vista Web Site:http://www.microsoft.com/vista Windows Vista TechCenter: http://technet.microsoft.com/en-us/windowsvista/aa905062.aspx