版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
第一篇区块篇IntegratedphoneandPDAPrimarilydataviewingInteroperabilitywithOutlookandExchange.NETCompactFrameworkASP.NETmobilecontrolsMobileDeviceSolutionsComplexdocumentauthoring,editingandreadingKeyboardcentricatthedeskKeyboardandmouseinputmethodsFull.NETframeworkavailableCentrinoSolutionsWindowsMobileWindowsXPComplexdocumentauthoring,editingandactivereadingNotetakingandinkannotatingKeyboardcentricatthedesk,penandkeyboardawayfromthedeskKeyboard,mousepluspen,ink,andspeechinputmethodsFull.NETframeworkpreinstalledPen,ink,handwritingandspeechrecognitionAPI’sCentrinoSolutionsViewandsomedataentryIntegratedPDAwithphoneInteroperabilitywithOffice,ExchangeandSQLServer.NETCompactFrameworkASP.NETmobilecontrolsIntelXscaleSolutionsWindows®CEOne-waynetworkInformationconsumptionSmartPersonalObjectsSmartphonePocketPCandPocketPCPhoneNotebookPCTabletPCNetworkDefenseHealthcheckupITchecks“health〞ofclientNetworkAccessControlClientswhopassgetnetworkaccessClientswhodonotpassarefixedorblocked(aka“quarantined〞)HealthmaintenanceQuarantinedclientscanbegivenaccesstoresourcestogethealthyFromHome
(VPN,Dialup)ReturningLaptopsConsultants
GuestsUnhealthy
DesktopsMicrosoftBusinessSolutionsERPPositioningProjectManagementandAccountingERPPrimarilyinUSandLatinAmericaMid-marketERPTypicallycustomizedforuniquebusinessprocessesGlobalERPMultinationalsAdvancedmanufacturersMid-marketERPRichout-of-the-boxfunctionalityGuidingPrinciplesProductiveIntegratedExtensibleCapableShortlearningcurveMinimaladministrativeoverheadToolsintegratedtightlyAutomatescommontasksCustomizableforyourprocessIntegrateswith3rdpartytoolsRemotelyaccessibleRobust,secure,scalableStagingArchitectureDataentryTestApplicationCenterCommerceWebCommerceCommerceDataCommerceWebCommerceCommerceDataApplicationCenterApplicationCenterDataACSClusterACSClusterClustercontrollerClustercontrollerDataLiveCommunicationsClientRoadmapLC1.2ClientPlatformMultipartyIMP2PVoice
andVideoMPOPGroupsRoamingSIPsupportGPOpolicymanagementLC1.5ClientPlatformRollupofQFEsMPOPAdditionsFederation/ArchivingNotificationHAAdditionsLC2.0ClientPlatformNextgenerationofRTCexperiencesMorecoming!20032H04LonghornEnterpriseDeploymentUpdateInternetFirewallFirewallFirewallRuntimeServersCorporateLAN–InternalServersCrawl/SearchLoadBalancedWebInfrastructureServersDevelopmentServersTestServersBusinessDataServersBusinessUsersDatabaseandStagingServersStagingServersDatabaseServersOfflineServersIndicatesStagedDataFlowCommunicateandcollaborateinamoresecuremanner
withoutsacrificinginformationworkerproductivityWindowsXPSP2
Blockvirusormaliciouscodeatthe“pointofentry〞
AtRiskTheSoftUnderbellySecurityIssuesToday1Source:ForresterResearch2Source:InformationWeek,26November20013Source:Netcraftsummary4Source:CERT,20035Source:CSI/FBIComputerCrimeandSecuritySurvey6Source:ComputerSecurityInstitute(CSI)ComputerCrimeandSecuritySurvey20027Source:CERT,20028Source:GartnerGroup14BdevicesontheInternetby2021135Mremoteusersby2005265%increaseindynamicWebsites3From2000to2002reportedincidentsrosefrom21,756to82,0944Nearly80percentof445respondentssurveyedsaidtheInternethasbecomeafrequentpointofattack,upfrom57percentjustfouryearsago590%detectedsecuritybreaches685%detectedcomputerviruses695%ofallbreachesavoidablewithanalternativeconfiguration7Approximately70percentofallWebattacksoccurattheapplicationlayer8ApplicationLayerAttacksIdentityTheftWebSiteDefacementUnauthorizedAccessModificationofData,LogsandRecordsTheftofProprietaryInformationServiceDisruptionImplicationsCompliance:SarbanesOxleyGrammLeachBlilelyUSPatriotActHIPAA ThePrivacyAct(CA)Basel2(EU)DataProtectionAct(EU)LitigationFileSharingPiracyHRIssuesShareholderSuitsCustomerImpactTypesOfSRPRulesPathRuleComparespathoffilebeingruntoanallowedpathlistUsewhenyouhaveafolderwithmanyfilesforthesameapplicationEssentialinwhenSRPsarestrictHashRuleComparestheMD5orSHA1hashofafiletotheoneattemptedtoberunUsewhenyouwanttoallow/prohibitacertainversionofafilefrombeingrunCertificateRuleChecksfordigitalsignatureonapplication(i.e.Authenticode)Usewhenyouwanttorestrictbothwin32applicationsandActiveXcontentInternetZoneRuleControlshowInternetZonescanbeaccessedUsewheninhighsecurityenvironmentstocontrolaccesstowebapplicationsSQLServer2005ThemesSupportability&QualityEnterpriseEnhancementsUnified&FlexibleAdministrationPatchSolutionsPrevention,Readiness,RecoveryEaseofusePatchInstallsPatchinintegratedstepIntegratedDatabaseServicesandBusinessIntelligenceFlexibleinstallmanagementAddvaluetoone-stepFailoverClusteringExpandedscriptingsupportTraditionalFirewallsWideopentoadvancedattacksPerformanceversus
securitytradeoffLimitedcapacityforgrowthHardtomanageCodeRed,NimdaSSL-basedattacksSecurityiscomplexITisalreadyoverloadedBandwidthtooexpensiveToomanymovingpartsNoteasilyupgradeableDon’tscalewithbusinessChoosingtheRightTypeofAssessment
VulnerabilityScanningFocusesonknownweaknessesOfthethree,requirestheleastexpertiseGenerallyeasytoautomatePenetrationTestingFocusesonknownandunknownweaknessesRequiresadvancedtechnicalexpertiseCarriestremendouslegalburdenincertaincountries/organizationsITSecurityAuditsFocusesonsecuritypoliciesandproceduresOfthethree,requiresthemostexpertiseWhendonerightisthemosteffectivetypeofassessmentPerimeterSecurityEvolutionWideopentoadvancedattacksApplication-levelprotectionPerformanceversus
securitytradeoffSecurityandperformanceLimitedcapacityforgrowthExtensibilityandscalabilityHardtomanageEasiertouseThe
advancedapplicationlayerfirewall,VPNandWebcache
solutionthatenablescustomerstomaximizeITinvestmentsbyimprovingnetworksecurityandperformanceAdvancedprotectionApplicationlayersecuritydesignedtoprotectMicrosoftapplicationsFast,secureaccessEmpowersyoutoconnectuserstorelevantinformationonyour
networkinacostefficientmannerEaseofuseEfficientlydeploy,manage,andenablenewusagescenariosIntroducing:ISAServer2004Fast,secureaccessEmpowersyoutoconnectuserstorelevantinfo.onyournetworkISAServer2004NewFeatures
ContinuedcommitmenttointegrationEnhancedarchitecture
HighspeeddatatransportUtilizeslatestWindowsandPChardwareSSLbridgingunloadsdownstreamserversWebcache
UpdatedpolicyrulesServecontentlocallyPre-fetchcontentduringlowactivityperiodsInternetaccesscontrol
User-andgroup-basedWebusagepolicyExtensiblebythirdpartiesComprehensiveauthentication
NewsupportforRADIUSandRSASecurIDUser-&group-basedaccesspolicyThirdpartyextensibilitySystemServiceAccountsLocalServiceandNetworkServiceNopasswordtomanageRunswithonlyslightlymorepermissionsthanAuthenticatedUserLocalServicecannotauthenticateacrossthenetwork,NetworkServiceauthenticatesasthecomputeraccountLocalSystemNopasswordtomanageBypassessecuritychecksUserAccountsRunwithlessprivilegethanLocalSystemStorespasswordasanLSAsecretCanbecomplextoconfigureWhat’sNewWithIPSec?ManagementIPSecurityMonitorCommand-linemanagementwithNetshLogicaladdressesforlocalIPconfigurationSecurityStrongercryptographicmasterkey(Diffie-Hellman)ComputerstartupsecurityPersistentpolicyforenhancedsecurityAbilitytoexcludethenameoftheCAfromcertificaterequestsBetterdefaultexemptionhandlingInteroperabilityIPSecfunctionalityovernetworkaddresstranslation(NAT)ImprovedIPSecintegrationwithNetworkLoadBalancingISAServer2004NewFeatures
NewmanagementtoolsanduserinterfaceMulti-networkarchitectureUnlimitednetworkdefinitionsandtypesFirewallpolicyappliedtoalltrafficPernetworkroutingrelationshipsNetworktemplatesandwizardsWizardautomatesnwkroutingrelationshipsSupports5commonnetworktopologiesEasilycustomizedforsophisticatedscenariosVisualpolicyeditorUnifiedfirewall/VPNpolicyw/onerule-baseDrag/dropeditingw/scenario-drivenwizardsXML-basedconfigurationimport-exportEnhancedtrouble-shootingAllnewmonitoringdashboardReal-timelogviewerContentsensitivetaskpanesEaseofUseEfficientlydeploy,manage,andenablenewusagescenariosHowToUseWindowsUpdateToconfigureAutomaticUpdates:SelectKeepmycomputeruptodateOpentheSystemapplicationinControlPanel1OntheAutomaticUpdatestab,selectthe
optionyouwant32OfficeUpdateBenefitsLimitationSinglelocationforofficepatchesandupdatesEasytouseCanbeconfiguredtoupdateconsumeror
enterprisesystemsDoesnotsupportAutomaticUpdates;updatingmustbeinitiatedmanuallyOfficeUpdateWebsite:
HowToUseOfficeUpdate1ClickCheckforUpdates2InstalltheOfficeUpdateInstallationEngine
(ifnotalreadyinstalled)3Selecttheupdatesyouwanttoinstall4ClickStartInstallation5HowToUseSUSOntheSUSserverConfiguretheSUSserverat
://<servername>/SUSAdminOneachSUSclientConfigureAutomaticUpdatesontheclienttousetheSUSserverUseGroupPolicy,manuallyconfigureeachclient,or
usescriptsSettheSUSserversynchronizationscheduleReview,test,andapproveupdates123HowToUseMBSADownloadandinstallMBSA(onceonly)1LaunchMBSA2Selectthecomputer(s)toscan3Selectrelevantoptions4ClickStartscan5ViewtheSecurityReport6SoftwareUpdateServiceDeploymentBestPractices(1)RevieweachsecuritypatchDownloadandinstallthepatchTesteachsecuritypatchbeforedeploymentConfigureatestlabUseatestSUSserverConsiderusingVirtualPCsinthetestlabUseastandardacceptancetestingprocedureSoftwareUpdateServiceDeploymentBestPractices(2)CompletethedeploymentPilotthedeploymentConfigureachildSUSservertoapproveupdatesConfigureaGPOsothatthepatchisdownloadedfromthepilotSUSserveronlybyspecifiedworkstationsIfthepilotfails,removeapprovalfromtheSUSserverandmanuallyuninstallthepatchHowToUseSMSToDeployPatchesOpentheSMSAdministratorConsole1Right-clickAllWindowsXPComputers,andthenselectAllTasks>DistributeSoftwareUpdates3Usethewizardtocreateanewpackageandprogram4Browsetothepatchtobedeployed5Configureoptionsforhowandwhenthepatchwillbedeployedtoclients6ExpandtheSiteDatabasenode2SMS–MBSAIntegrationMBSAintegrationincludedwithSMS2003andthe
SUSFeaturePackforSMS2.0ScansSMSclientsformissingsecurityupdatesusingmbsacli.exe/hfSMSdirectsclienttorunlocalMBSAscan1SMSserverparsesdatatodeterminewhichcomputersneedwhichsecurityupdates3Administratorpushesmissingupdatesonlytoclientsthatrequirethem4Clientperformsscan,returnsdatatoSMSserver2MBSABenefitsScanssystemsforMissingsecuritypatchesPotentialconfigurationissuesWorkswithabroadrangeof
MicrosoftsoftwareAllowsanadministratortocentrallyscanmultiplecomputerssimultaneously MBSAisafreetool,andcanbe
downloadedfrom
MBSAConsiderationsMBSAreportsimportantvulnerabilitiesPasswordweaknessesGuestaccountnotdisabledAuditingnotconfiguredUnnecessaryservicesinstalledIISvulnerabilitiesIEzonesettingsAutomaticUpdatesconfigurationInternetConnectionFirewallconfigurationMBSA–ScanOptionsMBSAhasthreescanoptionsMBSAgraphicaluserinterface(GUI)MBSAstandardcommand-line
interface(mbsacli.exe)HFNetChkscan(mbsacli.exe/hf)BusinessCaseFor
PatchManagementWhendeterminingthepotentialfinancialimpactofpoorpatchmanagement,considerDowntimeRemediationtimeQuestionabledataintegrityLostcredibilityNegativepublicrelationsLegaldefensesStolenintellectualproperty“WecommendMicrosoftforprovidingenhancedsecurityguidancetoitscustomersaswellasforsolicitinguserinputaspartoftheprocessofproducingthatguidance“ClintKreitnerPresident/CEO“NISTreviewedandprovidedtechnicalcomments&advice,thatwasincorporatedinthisguidance〞TimothyGranceManagerSystemsandNetwork
SecurityGroupCommentsSecurelymakee-mailavailabletooutsideemployeesExchangepublishingYouNeedTo…SecurelymakeinternalapplicationsavailableontheInternetWebandServerPublishingEnablepartnerstoaccessrelevantinformationonmynetworkIntegratedS2SVPNandFWSecureandflexibleremoteaccess,whileprotectingmycorporatenetworkIntegratedRRASVPNandFWSecurelyconnectmybranchofficestothecorporateofficeIntegratedFW,VPN,CacheControlInternetAccessandprotectmyclientsfrommaliciousInternettrafficFW,WebProxyEnsurefastaccesstothemostfrequentlyusedwebcontentCachingISADeliversRelationalReportingMultiplefacttablesFullrichnessthedimensions’
attributesTransactionlevelaccessStar,snowflake,3NF…Complexrelationships:Multi-grains,many-to-many,roleplaying,indirect…RecursiveselfjoinsSlowlychangingdimensionsTheUnifiedDimensionalModel–
TheBestOfRelationalAndOLAPOLAPCubesMultidimensionalnavigationHierarchicalpresentationFriendlyentitynamesPowerfulMDXcalculationsCentralKPIframework“Actions”LanguagetranslationsMultipleperspectivesPartitionsAggregationsDistributedsourcesVisualStudioTeamSystemChangeManagementWorkItemTrackingReportingProjectSiteVisualStudio
TeamFoundationIntegrationServicesProjectManagementProcessandArchitectureGuidanceVisualStudioIndustryPartnersDynamicCodeAnalyzerVisualStudio
TeamArchitectStaticCodeAnalyzerCodeProfilerUnitTestingCodeCoverageVisioandUMLModelingTeamFoundationClientVSProClassModelingLoadTestingManualTestingTestCaseManagementApplicationModelingLogicalInfra.ModelingDeploymentModelingVisualStudio
TeamDeveloperVisualStudio
TeamTestApplicationModelingLogicalInfra.ModelingDeploymentModelingClassModelingSQLServerCatalogReportServerXMLWebServiceInterfaceReportProcessingDeliveryDeliveryTargets(E-mail,SharePoint,Custom)RenderingOutputFormats(HTML,Excel,PDF,Custom)DataProcessingDataSources(SQL,OLEDB,XML/A,ODBC,Oracle,Custom)SecuritySecurityServices(NT,Passport,Custom)OfficeCustomApplicationBrowserSQLServer2000ReportingServices
ArchitectureCMProfileRunscustomizable
postconnectscriptScriptrunsRQCnotifier
with“resultsstring”ListenerRQSreceivesNotifier
“resultsstring”Comparesresultsto
possibleresultsRemovestime-outif
responsereceivedbut
clientoutofdateRemovesquarantinefilter
ifclientuptodateQuarantineVSAsTimerlimitstime
windowtoreceivenotifybeforeautodisconnectQ-filtersetstemporaryroutefiltertoquarantineaccessInternetRASClientRRASServerIASServerQuarantineRQC.exeandRQS.exeareintheWindowsServer2003ResourceKitQuarantineArchitectureWhatisVSTeamFoundation?SourceCodeControlWorkItemTrackingBuildAutomationProjectSiteReportingMicrosoftBIProductSuiteAnalysisServicesOLAP&DataMiningDataTransformationServicesSQLServerRelationalEngineReportingServicesManagementToolsDevToolsVisualStudio.NetExcelOWCVisioMapPointDataAnalyzerSharePointPortalServerProjectServerWindowsServerMBSBIApplicationsCurrentArchitectureTCP/IPRTCClientAPIUserAppRTPSIPPINTT.120ServerArchitectureApplicationManagedAPIsApplicationManagedAPIsWinsockStorageADDispatcherDataStoreInterfacesSPLScriptEngineRegistrar/PresenceSIPProxyServerApplicationInteractionApplication
1CRMApplication
2BillingApplication
3LoggingRequestModified
RequestTITLEAvailableTodayMicrosoft®Windows®SecurityResourceKitAssessingNetworkSecurityJune23,2004EAParchitectureTLSGSS_APIKerberosPEAPIKEMD5EAPPPP802.3802.5802.11Anything…methodlayerEAPlayermedialayerMS-CHAPv2TLSSecurIDPartnerSolutionsOfferingsVALUEProposition:
GetmorebusinessvaluefromyourinvestmentinOfficeFinanceSarbanes-OxleyBusinessScorecardExcelAdd-inforSQLServerAnalysisServicesOperationsSixSigmaHRRecruitingSalesProposalsSolutionAcceleratorsMicrosoftProductsOfficeSolutionAcceleratorsVALUEProposition:
GetmorebusinessvaluefromyourinvestmentinOfficeYourPeopleEPMInvolves….YourBusinessProcesses
YourOrganizationYourSoftwareTechnology&ToolsEnterpriseProjectManagementAnorchestrationofyourpeople,processes,organizationwithtechnologyYourBusinessProcesses…GovernancePrioritizationBudgetingHuman
Resources…
etc…InitiativesImplementMicrosoftOfficeProject2003fortheEnterpriseDecisions-CorporateGoalsandObjectivesExecutivesFinanceSalesandMarketingR&DIT/ISYourOrganization…StrategicInitiativesHRDevelopmentProjectsOperationalImprovementsOnAverage45-50%ofallProjectsarelinkedtoStrategicObjectives.RepresentativeRisksAndTacticsTacticalSolutionsEnterpriseRisksEmbodyTrustworthyComputingSecureEnvironmentalRemediationUnpatchedDevicesNetworkSegmentationThroughIPSecUnmanagedDevicesSecureRemoteUserRemoteandMobileUsersTwo-FactorforRemoteAccessandAdministratorsSingle-FactorAuthenticationManagedSourceInitiativesFocusControlsAcrossKeyAssetsRemoteAccessSecurity
ThreatRequirementSolutionMalicious
usersTwofactorauthenticationSmartCards
forRASMalicious
softwareEnforceremotesystemsecurityconfigurationConnectionManager,customscriptsandtoolsprovidedintheWindows2003resourcekitCorporateSecurityGroupOrganizationCorporateSecurityGroupThreat,Risk
Analysis,andPolicyAssessmentand
ComplianceMonitoring,IntrusionDetection,andIncidentResponseSharedServices
OperationsThreatandRisk
AnalysisPolicy
DevelopmentProduct
EvaluationDesign
ReviewStructure
StandardsSecurity
ManagementSecurity
AssessmentComplianceand
RemediationMonitoringand
IntrusionDetectionRapidResponse
andResolution
ForensicsIT
InvestigationsPhysicaland
RemoteAccessCertificate
AdministrationSecurity
ToolsInitiative
ManagementServerFunctionsOperationalInfrastructureServerWorkloadsFocusApplication/WebServerUnixintegrationservicesWorkloadsSolutionsApplicationPlatformInformationWorkerInfrastructureDatabaseHighPerformanceComputingSoftwareDistributionVirtualizationOperationsMgmtTerminalServerEmailCollaborationBranchOfficeMediumBusinessSmallBusinessNetworkingRemoteAccessSecurityIdentityMgmtStorage(file,portal)PrintWhatIsMapPointWebService?Functionalities/APIsMaps,Geocoding,ReverseGeocoding,ProximitySearch,FindAddressetc.DevelopmentToolsVisualStudio.Net,Linux,VisualBasic,Mac,Java,C#…XMLWebService
PointsofInterestDatabaseofmorethan200,000and16millionbusinesslistingsCartographicdataExtensivegeographiccoveragein19countriesinEuropeandNorthAmerica.NoUIconstraints;deviceindependent.Integration
intoabroadrangeof
differentapplications
anddevices.20042005WindowsSmallBusinessServer2003SP1WindowsServer2003for64-BitExtendedSystemsWindowsServer2003ServicePack1(SP1)WindowsXPTabletEdition2005WindowsXPMediaCenterEdition2005WindowsXPServicePack2(SP2)VirtualServer2005AdditionalFeaturePacks(e.g.WindowsUpdateServices)WindowsServer:Codename“Longhorn〞Beta1WindowsClient:Codename“Longhorn〞Beta1WindowsServer2003Update:Codename“R2〞ReleaseRoadmap第二篇表格篇MicrosoftPatchSeverityRatingsSecurityBulletinList:
RatingDefinitionCriticalExploitationcouldallowthepropagationofanInternetwormImportantExploitationcouldresultincompromiseofuserdataortheavailabilityofprocessingresourcesModerateExploitationisserious,butismitigatedtoasignificantdegreebydefaultconfiguration,auditing,needforuseraction,ordifficultyofexploitationLowExploitationisextremelydifficultorimpactisminimalPatchingTimeFramesSeverityratingRecommendedpatchingtimeframeRecommended
maximumpatchingtimeframeCriticalWithin24hoursWithintwoweeksImportantWithinonemonthWithintwomonthsModerateDependingonexpectedavailability,waitfornextservicepackorpatchrollupthatincludesthepatch,ordeploythepatchwithinfourmonthsDeploythepatchwithinsixmonthsLowDependingonexpectedavailability,waitfornextservicepackorpatchrollupthatincludesthepatch,ordeploythepatchwithinoneyearDeploythepatchwithinoneyear,orchoosenottodeployatallImprovingThePatchingExperienceYourneedMicrosoft’sresponseReducepatchfrequencyReducedfrequencyofnon-emergencypatchreleasesfromonceperweektooncepermonthReducepatchingcomplexityReducednumberofpatchinstallertechnologiesReduceriskofpatchdeploymentImprovedpatchqualityandintroduced
patchrollbackcapabilityReducepatchsizeDeveloped“deltapatching”technologyto
reducepatchsizeReducedowntimeReducedpatch-relatedrebootsImprovetoolconsistencyDevelopingconsistenttoolsImprovetoolcapabilitiesDevelopingmorecapabletoolsChoosingAPatch
ManagementSolutionCustomertypeScenarioSolutionConsumerAllscenariosWindowsUpdateSmallorganizationHasnoWindowsserversWindowsUpdateHasonetothreeWindows2000
ornewerserversandoneITadministratorMBSAandSUSMedium-sizedorlargeenterpriseWantsapatchmanagementsolutionwithbasiclevelofcontrolthatupdatesWindows2000andnewerversionsofWindowsMBSAandSUSWantsasingleflexiblepatchmanagementsolutionwithextendedlevelofcontroltopatch,update,anddistributeallsoftwareSMSPatchManagementSolutionForMedium-SizedAndLargeOrganizationsCapabilitySUS1.0SMS2003
Supported
Platformsfor
Content
Windows2000
WindowsXP
WindowsServer2003
WindowsNT4.0
Windows98
Windows2000WindowsXP
WindowsServer2003
Supported
ContentTypes
Securityandsecurity
rolluppatches,critical
updates,andservice
packsfortheabove
operatingsystems
Allpatches,servicepacks,and
updatesfortheaboveoperating
systems;supportspatch,
update,andapplication
installationsforMicrosoftand
otherapplications
Patch
Distribution
Control
Basic
AdvancedOtherSessionsOfInterestWIN280MicrosoftVirtualServer2005:TechnicalOverviewMon,May24
1:30-2:45PMRoom20AWINC28Q&AWiththeVirtualServer
TeamTues,May25
1:30–2:45PMCabana13WIN383UsingMicrosoftVirtualServer2005toInstalla
2-NodeClusterofVirtual
MachinesTues,May25
3:15-4:30PMRoom31ABCWIN381AdvancedConfigurationsScenariosforVirtualServer2005Tues,May25
5:00-6:15PMRoom31ABCWINC10ConsolidatingNT4ApplicationsUsingWindowsVirtualServer2005Wed,May26
10:15-11:30AMCabana12WINC13CreatingaVirtualTestLabwithMicrosoftVirtualServer
2005Wed,May26
5:30-6:45PMCabana12TheImportanceOfProactivePatchManagementAttackPatchreleasedateAttackdateNumberofdayspatchwasavailablebeforetheattackTrojan.KahtMar17,2003May,5200349SQLSlammerJul24,2002Jan24,2003184Klez-EMar29,2001Jan17,2002294NimdaOct17,2000Sept18,2001336CodeRedJun18,2001Jul16,200128DREADHigh(3)Medium(2)Low(1)DamagepotentialAttackercanretrieveextremelysensitivedataandcorruptordestroydataAttackercanretrievesensitivedatabutdolittleelseAttackercanonlyretrievedatathathaslittleornopotentialforharmReproduc-abilityWorkseverytime;doesnotrequireatimingwindowTiming-dependent;worksonlywithinatimewindowRarelyworksExploitabilityBartSimpsoncoulddoitAttackermustbesomewhatknowledgeableandskilledAttackermustbeVERYknowledgeableandskilledAffectedusersMostorallusersSomeusersFewifanyusersDiscoverabiltyAttackercaneasilydiscoverthevulnerabilityAttackermightdiscoverthevulnerabilityAttackerwillhavetodigtodiscoverthevulnerabilityMicroIssuesare88%Simpletofix.Create“Noise〞Fiveissuesrepresent88%ofallupgradeissuesDefaultproperties52%Property/methodnotupgraded13%Property/methoddifferentbehavior12%ModulemethodsofCOMobjects7%Null/IsNull4%AnalysisServiceandDTSMigrationWizardsNonewMDACbitsReducedSQLDatabaseservicesdowntimeUpgradeEditionsUpgradeLanguagePlatformSQL2005Beta2DeveloperEditionSQL2000Enterprise,Standard,Developer,&PersonalEditionsSP3orhigherJPNIntelX86IntelIA64ENUIntelAMD64ExampleGoalsProjectGoalInthevulnerabilityscanningproject,allcomputersrunningWindows2000ServerandWindowsServer2003onthesubnets/24and/24willbescannedforthefollowingvulnerabilitiesberemediatedasstated.VulnerabilityRemediationRPCoverDCOMvulnerability(MS03-026)InstallMicrosoftsecuritypatches03-026and03-39.AnonymousSAMenumerationConfigureRestrictAnonymousto:2onWindows2000Server1onWindowsServer2003GuestaccountenabledDisableGuestaccount.Greaterthan10accountsinthelocalAdministratorgroupMinimizethenumberofaccountsontheadministratorsgroup.ExampleScopeStatementComponentsExampleTargetAllserversrunning:*Windows2000Server*WindowsServer2003TargetareaAllserversonthesubnets:/24/24TimelineScanningwilltakeplacefromJune3rdtoJune10thduringnon-criticalbusinesshoursVulnerabilitiestoscanforRPCoverDCOMvulnerability(MS03-026)AnonymousSAMenumerationGuestaccountenabledGreaterthan10accountsinthelocalAdministratorgroupWhattoplanfor…ProjectPhasePlanningElementsPre-assessmentScopeGoalsTimelinesGroundrulesAssessmentChoosingtechnologiesPerformassessmentOrganizeresultsPreparingresultsEstimateriskpresentedbydiscoveredweaknessesCreateaplanforremediationIdentifyvulnerabilitiesthathavenotbeenremediatedDetermineimprovementinnetworksecurityovertimeReportingyourfindingsCreatefinalreportPresentyourfindingsArrangefornextasses
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2025交通事故致人死亡赔偿协议书14篇
- 借款借贷合同协议书七篇
- 补水美容病因介绍
- 内蒙古通辽市(2024年-2025年小学六年级语文)统编版能力评测(下学期)试卷及答案
- 全国赛课一等奖初中统编版七年级道德与法治上册单元思考与行动《追求美好人生》精美课件
- (2024年)艺术学校建设项目可行性研究报告
- 【中职专用】中职对口高考-机电与机制类专业-核心课-模拟试卷1(河南适用)(答案版)
- 2023年天津市和平区高考语文三模试卷
- 2023年复合管道项目融资计划书
- 蔬菜园艺工中级考试题
- GB/T 30002-2024儿童牙刷通用技术要求
- 动画制作员(高级工)技能鉴定理论考试题库(含答案)
- 真空蒸镀中部分金属熔点及不同气压下蒸发温度
- 中日标准件对照表
- (完整版)密闭式静脉输液技术操作评分标准
- 《贲门失弛缓症》PPT课件课件
- 坝基渗漏问题分析
- 汽车连杆加工工艺规程及夹具设计毕业论文 (1)
- RP90型吉他综合效果处理器操作手册
- 外研版小学英语(三起)五年级下册单词表(含音标)
- 小化肥生产原理及过程
评论
0/150
提交评论