SP2 Microsoft's Active Defense Strategy

  
        Windows and Microsoft itself, which have always been favored by viruses and hackers, will change after Microsoft’s “active defense” tactics are introduced.

so much noise that many people uneasy vulnerability had been lurking inside of Windows seems to breathe easy. On August 4th, Microsoft officially released the second patch of the much-anticipated Windows XP system, which included all the patches since the release of Windows XP SP1. This is not only the largest upgrade since Windows XP was released in late 2001, but more importantly, SP2 has focused more on preventing other potential security risks. "SP2 is a revolutionary measure by Microsoft. It replaces the previous "passive protection" software security protection model and concept with 'active protection'." Sun Jiandong, deputy general manager of Microsoft (China) Co., Ltd., was interviewed by reporters not long ago. This evaluation.

However, as "the largest free upgrade package Microsoft has ever made", the expected response of SP2 in the market is not satisfactory. Shortly after the release of SP2, IBM has begun to warn its employees, before the full test of SP2, it is recommended to suspend the deployment of SP2. "There are some conflicts between SP2 and IBM workstation programs," IBM explained. "SP2 may change the behavior of web browsers and cause incompatibilities with some applications."

Even Microsoft itself is already Its official website details a series of issues that users may encounter after installing SP2. These applications, which may conflict with SP2, include several Microsoft products, as well as antivirus tools, web server software, and several computer game software. Microsoft's advice is to encourage enterprise users to use the "software upgrade service" or "system management server" that comes with the operating system to upgrade before all problems are satisfactorily resolved.

But these troubles don't seem to affect Microsoft's continued commitment to information security. In addition to the "active defense" feature in SP2, Microsoft's other firewall product ISA Server 2004 (Internet Security and Acceleration Server) targeting the enterprise market will also be available in September, especially for China. The market launched the Simplified Chinese version, which is the most powerful action in the information security field in the four years since ISA Server 2000.

All aspects of the move to the background of the "Microsoft into the anti-virus software market" rumors in the industry, making the situation look quite subtle. What kind of changes will happen to the Windows operating system family, which has always been favored by viruses and hackers, after the launch of Microsoft's "active defense" tactics?

A Secure Shield called "Active Defense"

"Strictly speaking, SP2 is not just a service package, because the investment we make on SP2 is very huge, if SP2 is not considered a new version of Windows." Sun Jiandong said, "The focus of this investment is security, which uses an active protection technology
, which fundamentally enhances Windows against virus intrusion. According to Zhu Xiaowen, director of security marketing at Microsoft (China) Co., Ltd., SP2 enhances the security of Windows XP from the aspects of network, email and instant messaging, web browsing, memory and maintenance. SP2 Chinese version will be 8 Completed on the 21st of the month, starting from September 15th, users can get the Chinese version of Windows XP SP2 for free through various channels.

The chain reaction brought about by SP2 is not just a change in its anti-virus "attitude". Before the official release of the English version of Windows XP SP2, many analysts had predicted that "the biggest feature of this version of the system is the addition of the security center function, and the personal firewall developed by Microsoft itself is bundled. Improve." Even the industry analysts said that this indicates that Microsoft will be officially involved in the anti-virus software market.

In fact, for Microsoft, which has always been good at "bundling tactics", it is only bundled with a powerful "action interceptor" in Widows XP SP2, similar to personal firewall products. Different from the traditional anti-virus software, this product bundled with SP2 does not scan the computer according to the virus code, but directly monitors the various processes running on the computer, and it is enabled by default, and will not be in the operating system. The default setting of the necessary function is OFF. The Security Center will manage or display the security settings of the system and the security software of the relevant vendors. It is worth noting that according to Wang Jianbing, product manager of R&D department of Microsoft (China) Co., Ltd., SP2 also specially updated support for wireless network connection, Bluetooth, Tablet PC and Meida Center.

Although SP2 can prevent viruses such as hackers and worms from invading computer systems, it cannot prohibit malicious programs that have been stored on the computer's hard disk from spreading data or information to the network. Therefore, the utility of Windows Firewall is actually Those more professional firewall products are not a replacement relationship, but more is just the strengthening and improvement of Microsoft's product features. After all, Windows family products account for more than 90% of the desktop operating system market share, and some of its security vulnerabilities have become the test field for programmers to show off their capabilities in recent years.

But this new feature in SP2 has caused a lot of uneasiness and vigilance against many anti-virus software vendors. “It’s still too early to say that SP2 is good. SP2 is an important step towards the right goal, but our concerns still exist, as it used to be,” said Alfred Huger, senior engineering director at Symantec, although still It is difficult to have a network virus that can break through the SP2 defense system, but this possibility is not non-existent. "The SP2 system can block the shock wave virus, but the network virus has no end, and the virus makers will look for other attacks. "

Although there has been a rumor in the industry since June that Microsoft wants to acquire Symantec or NAI and enter the information security field, similar speculations have not stopped in the last two years. But not only Symantec and NAI categorically denied these rumors, but Microsoft has also been low-key, just saying that it is investing more in its platform products to enable third parties to better build and provide more effective defense for customers. Virus engine and solution. For example, Jiangmin Technology, one of Microsoft's security strategic partners in China, has already passed the SP2 system security center certification for its product KV2004 international version.

Microsoft admitted at the end of July that it will develop a new stand-alone anti-virus product based on the two software companies GeCad and Pelican acquired in 2003, but the specific implementation plan is still only " preliminary stage".

Offense is the best defense

However, compared to the personal market, Microsoft has taken a big step in the enterprise market for information security. Almost at the same time as SP2 was released, Microsoft announced at the Toronto Global Partner Conference on July 13 that it would completely update the ISA Server 2000, a network application layer firewall product released four years ago. Although the pace is very slow, the simplified Chinese version of ISA Server 2004, which will officially debut in China in September, is quite mature, which at least shows that Microsoft has actually been involved in the anti-virus software market, and this seems to be an understatement of product upgrades. Undoubtedly, it also implies Microsoft's greater ambitions.

"For companies, they want to use the least amount of IT investment to produce the best possible results, that is, to improve the cost performance, on the one hand to improve the return on investment, on the other hand, to reduce costs. This is what Microsoft is now emphasizing. Application layer protection reasons." On August 17, Joseph Landes, product manager of Microsoft Business Security and Technology
, said in an interview: "ISA Server 2004 is a platform-oriented product for the application layer. "

For the enterprise-class market that Microsoft has not always had an advantage but is lucrative, the launch of ISA Server 2004 is a very clever entry point. "95% of security issues are caused by misconfigurations, that is, the human factor is the main one, and most of them can be avoided by properly deploying firewall products." Landes said that traditional firewall products tend to ignore the application layer. Protection, and the difficulty of configuration and management is relatively large. The opportunity for Microsoft is coming.

ISA Server 2004 with deep protection, easy operation and fast access capabilities is actually a product that combines application layer firewall, VPN and Web cache. According to its own positioning, It does not conflict with traditional firewall products located between the internal network and the Internet. It can be seen as adding a special protection measure to the application layer of the internal network of the enterprise. After all, Microsoft is only a latecomer in this field, and direct confrontation with traditional leaders is not good for Microsoft.

And Microsoft's marketing strategy still reflects a clear "platform" style. On the hardware side, HP and Dell have introduced hardware firewalls pre-installed with ISA Server 2004; in terms of software, Microsoft has also pulled out McAfee, Panda software, GFi and other third-party partners based on its powerful appeal, based on ISA Server platform. For secondary development, there are also technical
partners like Symantec and RSA. In addition, in the sales model, Microsoft adopted the standard version of ISA Server 2004 to purchase licenses according to the number of CPUs, not the number of users. This means that Microsoft will ignore how many users are accessing the server connected to the Internet.

"Security is one of the biggest and most important challenges we've encountered in the industry. It's not a problem that can be solved by just fixing the bug." This is Gates in the year 3 What I said in the month. In the face of endless attacks like hackers, Microsoft's SP2, which was built with hundreds of millions of dollars, has been in trouble since its launch, but Gates is not ready to give up, and wants to go further.

How secure is SP2?

The Windows XP SP2 service pack, which took 9 months and cost nearly $1 billion, was officially released. Bill Gates described SP2 as the largest free upgrade to Windows' history, and this update has delayed Microsoft's other development plans, including the next-generation version of the Windows operating system, Longhorn.

Windows XP continues to expose security vulnerabilities, Microsoft is facing tremendous pressure from users, Microsoft eventually had to consider security issues as the first priority for Windows XP. To enhance the security of Windows XP, Microsoft even called a number of Longhorn developers to do Windows XP updates. Steve Ballmer even said that SP2 is a major patch, even if Microsoft wants to take anything from Longhorn, or even delay the launch of Longhorn, SP2 is a priority.

Microsoft claims that SP2 has a comprehensive set of protection systems that make the operating system more immune to external attacks. And said that SP2 is Microsoft's safest Windows to date, which means that SP2 is not a virtual name, Microsoft is really improving the security of the system. But things are obviously not as simple as imagined. When SP2 was released, it broke the issue that upgrading to SP2 might conflict with some programs, which made Microsoft have to give the organization users four months of evaluation time.

The experience of the past few years has made software giant Microsoft understand that security is not a simple matter, Microsoft needs to cut into the security field from various angles. Red Code Virus and Nimda forced Microsoft to build a 10-year trust computing program. The Slammer virus made Microsoft pay more attention to the patch, and the Blaster virus made Microsoft determined to launch the SP2 service. The package, and ultimately prompted Microsoft to introduce a mechanism to reward the author of the virus.

The question is, is upgrading to SP2 a sign that we are safe? This may be the biggest question in every user's mind. Although SP2 can improve the safety factor of computers, security experts have predicted that SP2 will be broken. PhrX Solutions Security Researcher Thor Larholm, who has downloaded SP2 and is analyzing it

Copyright © Windows knowledge All Rights Reserved