




版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、Microsoft Security StrategySteven AdlerProduct ManagerMicrosoft EMEASession AgendaFocus on Customer ChallengesMicrosoft Security StrategySecure Windows InitiativeStrategic Technology Protection ProgramTrustworthy ComputingBuilding the secure platform.NET FrameworkWindows .NETSummaryQuestionsTechnolo
2、gy, Process, PeopleWhat are the challenges?Products lack security featuresProducts have bugsInsufficient technical standardsDifficult to stay up-to-dateDesign for securityRoles & responsibilitiesVigilanceBusiness continuity plansStay up-to-date with security developmentProblem recognitionSkills shor
3、tageHuman errorProcessPeopleTechnologyTrustworthy ComputingStrategic Technology Protection ProgramSecure Windows InitiativeMicrosoft Security StrategySecure Windows Initiative“Engineering For Security”Goal: Eliminate Every Security Vulnerability Before The Product ShipsPeopleProcessTechnologyIndustr
4、y YardstickSource: Security Focus Secure Windows InitiativePeopleTrain, and keep current, every developer, tester, and program manager in the specific techniques of building secure productsProcessMake security a critical factor in design, coding and testing of every product Microsoft buildsCross-gro
5、up design & code reviewsSecurity Threat Analysis part of every design specRed Team testing and code reviewsFocus not confined to buffer overrunsSecurity bug feedback loop & code sign-off requirements External reviews and testing by consultants and publicTechnologyBuild tools to automate everything p
6、ossible in the quest to code the most secure productsPrefix and Prefast for buffer overrun detectionUpdated as new vulnerabilities foundVisual C+ 7.0 compiler improvementsDomain-specific tools (i.e. RPC security stress)Secure Windows InitiativeExternal Security ReviewFIPS 140-1 evaluation of Cryptog
7、raphic Service Provider (CSP) CompletedGovernment validation of base crypto algorithms in WindowsCommon Criteria evaluation In PreparationEvaluation of Windows source code against International security criteria for evaluating Third party expert review of key componentsSource code licensed to over 8
8、0 universities, labs, and government agenciesGoal: Help customers secure their Windows SystemsPeopleProcessTechnologyStrategic TechnologyProtection ProgramStrategic Technology Protection Program - Customers Need Our HelpI didnt know which patches I neededI didnt know where to find the updatesI didnt
9、 know which machines to updateWe updated our production servers, but the rogue servers got infectedMore than 50% of the customers affected by Code Red were not patched in time for NimdaSTPP: “Get Secure”Coming - Enterprise Security ToolsMicrosoft Baseline Security AnalyzerSMS security patch rollout
10、toolWindows Update Auto-update clientNow - Microsoft Security ToolkitServer oriented security resources.New server security tools and updates, Windows Update bootstrap client for Windows 2000Now - Security Assessment Program OfferingAvailable immediately through MCS/PSSNow - Free Virus Support Hotli
11、neContact your local PSS officeGet SecureMicrosoft Security ToolkitGets Windows NT and 2000 systems to secure baseline, even disconnected netAutomates server updatesOne-button wizard and SMS ScriptsUpdates and Patches Includes all Service Packs and critical OS and IIS patches through 10/15HFNetchk:
12、patch level verifierIIS Lockdown & URLScanSTPP: “Stay Secure”Ongoing - Enhanced Product SecurityProvide greater security enhancements in the releases of all new products, including theWindows .NET Server family Spring 2002 - Federated Corporate Windows Update ProgramAllows enterprise to host and sel
13、ectWindows Update contentSpring 2002 - Windows 2000 Service Pack (SP3)Provide ability to install SP3 + security rollupwith a single rebootJan. 2002 - Windows 2000 Security Rollup PatchesBundle all security fixes in single patchesReduces reboots and administrator burdenCorporate Update Server Solutio
14、nAutomatic Update (AU) clientAutomatically download and install critical updatesSecurity patches, high impact bug fixes and new drivers when no driver is installed for a deviceChecks Windows Update service or Corporate Update server once a dayNew! Install at schedule time after automatic downloads A
15、dministrator control of configuration via registry-based policySupport for Windows .NET Server, Windows XP and Windows 2000Update serverCorporate hosted WU server to support download and install of critical updates through AU clientServer synchronizes with the public Windows Update serviceSimple adm
16、inistrative model via IE Updates are not made available to clients until the administrator approves themRuns on Windows .NET Server and Windows 2000 ServerTrustworthy ComputingGoal: Make devices powered by computers and software as trustworthy as devices powered by electricity. A Trust TaxonomyAvail
17、abilityAt advertised levelsSuitabilityFeatures fit function IntegrityAgainst data loss or alterationPrivacyAccess authorized by end-userReputationSystem and provider brandSecurityResists unauthorized accessQualityPerformance criteriaDev PracticesMethods, philosophyOperationsGuidelines and benchmarks
18、Business PracticesBusiness modelPoliciesLaws, regulations, standards, normsIntentManagement assertionsRisksWhat undermines intent, causes liabilityImplementationSteps to deliver intentEvidenceAudit mechanismsGoalsMeansExecutionBuilding the secure platformGoal: Provide IT with a secure, integrated fo
19、undation for managing how users, business, and technologies connect.Infrastructure (PKI, Directory)Security in depthNetwork (IPSec, Wireless, VPN)Device (PDA, Laptops, PCs, Servers)ApplicationManagementFront EndTypical Application ArchitectureUsersBack EndAuthenticationNetwork AccessAuthorizationAud
20、itAlertsFront EndSecure Network AccessUsersBack EndAuthorizationAuthenticationNetwork AccessFirewallVPNWirelessIPSECAuditAlertsFront EndFlexible AuthenticationUsersBack EndBasicHTTP DigestKerberosCertificatesSmartcardsAuthenticationNetwork AccessAuthorizationAuditAlertsFront EndRich Access ControlsUsersBack EndAuthenticationNetwork AccessAuthorizationAuditAlertsAccess Control
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 二零二五年度草原雇佣放羊与生态旅游合作合同
- 南充经济开发区投资集团有限公司2024年招聘笔试参考题库附带答案详解
- 交通法学概论(山东联盟)知到智慧树章节测试课后答案2024年秋山东交通学院
- 2025年安庆市大观控股集团有限公司校园招聘3人笔试参考题库附带答案详解
- 2025年中储粮集团纪检监察组招聘(4人)笔试参考题库附带答案详解
- 边牧抚养知识培训课件
- 2025中联重科开封工业园招聘280人笔试参考题库附带答案详解
- 宠物行业知识培训课件
- 中医面部知识培训课件下载
- 2025年上半年佛山市顺德区大良街道招考工作人员易考易错模拟试题(共500题)试卷后附参考答案
- 员工安全风险辨识及管控措施
- 水利水电工程施工质量管理及验收规程讲课稿课件
- 介入科规章制度
- 《大气污染物控制工程》-挥发性有机物污染控制
- 《连续性肾替代治疗容量评估与管理专家共识》解读课件
- 健康产业数字化服务平台建设及运营模式
- 现代家政导论-课件 5.2.1认识国外家政服务业发展
- 2024湖北事业单位联考C类真题解析历年高频难、易错点500题模拟试题附带答案详解
- GB/T 44723-2024氢燃料内燃机通用技术条件
- 驾驶员职业健康知识培训
- 【课件】程式与意蕴-中国传统绘画+课件高中美术人美版(2019)美术鉴赏
评论
0/150
提交评论