




版權說明:本文檔由用戶提供并上傳,收益歸屬內容提供方,若內容存在侵權,請進行舉報或認領
文檔簡介
1、Session AgendaFocus on Customer ChallengesMicrosoft Security StrategySecure Windows InitiativeStrategic Technology Protection ProgramTrustworthy ComputingBuilding the secure platform.NET FrameworkWindows .NETSummaryQuestionsTechnology, Process, PeopleWhat are the challenges?Products lack security fe
2、aturesProducts have bugsInsufficient technical standardsDifficult to stay up-to-dateDesign for securityRoles & responsibilitiesVigilanceBusiness continuity plansStay up-to-date with security developmentProblem recognitionSkills shortageHuman errorProcessPeopleTechnologyMicrosoft Security StrategySec
3、ure Windows Initiative“Engineering For Security”Goal: Eliminate Every Security Vulnerability Before The Product ShipsIndustry YardstickSource: Security Focus http:/ Windows InitiativePeoplePeopleTrain, and keep current, every developer, tester, Train, and keep current, every developer, tester, and p
4、rogram manager in the specific techniques of and program manager in the specific techniques of building secure productsbuilding secure productsProcessProcessMake security a critical factor in design, coding and Make security a critical factor in design, coding and testing of every product Microsoft
5、buildstesting of every product Microsoft buildsCross-group design & code reviewsCross-group design & code reviewsSecurity Threat Analysis part of every design specSecurity Threat Analysis part of every design specRed Team testing and code reviewsRed Team testing and code reviewsFocus not confined to
6、 buffer overrunsFocus not confined to buffer overrunsSecurity bug feedback loop & code sign-off requirements Security bug feedback loop & code sign-off requirements External reviews and testing by consultants and publicExternal reviews and testing by consultants and publicTechnologyTechnologyBuild t
7、ools to automate everything possible in the Build tools to automate everything possible in the quest to code the most secure productsquest to code the most secure productsPrefix and Prefast for buffer overrun detectionPrefix and Prefast for buffer overrun detectionUpdated as new vulnerabilities foun
8、dUpdated as new vulnerabilities foundVisual C+ 7.0 compiler improvementsVisual C+ 7.0 compiler improvementsDomain-specific tools (i.e. RPC security stress)Domain-specific tools (i.e. RPC security stress)Secure Windows InitiativeExternal Security ReviewFIPS 140-1 evaluation of Cryptographic Service P
9、rovider (CSP) CompletedGovernment validation of base crypto algorithms in WindowsCommon Criteria evaluation In PreparationEvaluation of Windows source code against International security criteria for evaluating Third party expert review of key componentsSource code licensed to over 80 universities,
10、labs, and government agenciesGoal: Help customers secure their Windows SystemsStrategic TechnologyProtection ProgramStrategic Technology Protection Program - Customers Need Our HelpI didnt know which patches I neededI didnt know where to find the updatesI didnt know which machines to updateWe update
11、d our production servers, but the rogue servers got infectedMore than 50% of the customers affected by Code Red were not patched in time for NimdaSTPP: “Get Secure”Coming - Enterprise Security ToolsMicrosoft Baseline Security AnalyzerSMS security patch rollout toolWindows Update Auto-update clientNo
12、w - Microsoft Security ToolkitServer oriented security resources.New server security tools and updates, Windows Update bootstrap client for Windows 2000Now - Security Assessment Program OfferingAvailable immediately through MCS/PSSNow - Free Virus Support HotlineContact your local PSS officeGet Secu
13、reMicrosoft Security ToolkitGets Windows NT and 2000 systems to secure baseline, even disconnected netAutomates server updatesOne-button wizard and SMS ScriptsUpdates and Patches Includes all Service Packs and critical OS and IIS patches through 10/15HFNetchk: patch level verifierIIS Lockdown & URLS
14、canSTPP: “Stay Secure”Ongoing - Enhanced Product SecurityProvide greater security enhancements in the releases of all new products, including theWindows .NET Server family Spring 2002 - Federated Corporate Windows Update ProgramAllows enterprise to host and selectWindows Update contentSpring 2002 -
15、Windows 2000 Service Pack (SP3)Provide ability to install SP3 + security rollupwith a single rebootJan. 2002 - Windows 2000 Security Rollup PatchesBundle all security fixes in single patchesReduces reboots and administrator burdenCorporate Update Server SolutionAutomatic Update (AU) clientAutomatica
16、lly download and install critical updatesSecurity patches, high impact bug fixes and new drivers when no driver is installed for a deviceChecks Windows Update service or Corporate Update server once a dayNew! Install at schedule time after automatic downloads Administrator control of configuration v
17、ia registry-based policySupport for Windows .NET Server, Windows XP and Windows 2000Update serverCorporate hosted WU server to support download and install of critical updates through AU clientServer synchronizes with the public Windows Update serviceSimple administrative model via IE Updates are no
18、t made available to clients until the administrator approves themRuns on Windows .NET Server and Windows 2000 ServerTrustworthy ComputingGoal: Make devices powered by computers and software as trustworthy as devices powered by electricity. A Trust TaxonomyBuilding the secure platformGoal: Provide IT with a s
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯系上傳者。文件的所有權益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網頁內容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
- 4. 未經權益所有人同意不得將文件中的內容挪作商業或盈利用途。
- 5. 人人文庫網僅提供信息存儲空間,僅對用戶上傳內容的表現方式做保護處理,對用戶上傳分享的文檔內容本身不做任何修改或編輯,并不能對任何下載內容負責。
- 6. 下載文件中如有侵權或不適當內容,請與我們聯系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 某童裝品牌戰略咨詢計劃書
- 地理(山東青島卷)(A4考試版)
- 大班音樂歌唱春天幼兒讀物幼兒教育教育專區
- 上海虹口區2024-2025學年下學期七年級期末考試英語試題(含答案無聽力原文及音頻)
- 試劑分析性能評估模板資料講解
- 自動控制系統設計曲面印刷機
- 2025年遼寧省中考英語模擬試題(二)
- 【高中語文】《登岳陽樓》課件+統編版高一語文必修下冊
- 建筑施工特種作業-橋(門)式起重機司機真題庫-4
- 山東美術英文題目及答案
- 農機停放場管理制度
- 2025年浙江省嘉興市南湖區中考二模英語試題(含答案無聽力原文及音頻)
- T/SHPTA 071.1-2023高壓電纜附件用橡膠材料第1部分:絕緣橡膠材料
- 生產基層管理培訓課程
- 2025至2030年中國豬預混料行業投資前景及策略咨詢研究報告
- 2025年中央八項規定精神學習教育應知應會考試題庫(含答案)
- 云南2025年云南省社會科學院中國(昆明)南亞東南亞研究院招聘高層次人才筆試歷年參考題庫附帶答案詳解
- 2025年浙江省溫州市樂清市中考二模語文試題(含答案)
- 果園蘋果買賣合同協議書
- 分析定向增發“盛宴”背后的利益輸送現象、理論根源及制度原因
- 美容院開店流程與注意事項
評論
0/150
提交評論