October 02, 2007

Security researchers look beyond Vista

At the BlueHat meeting, many third-party security personnel came away impressed with Microsoft's adoption of their own security measures and techniques

The improved security in Microsoft's newest software products may leave some security researchers looking elsewhere for work.

That was the message that some security professionals took away from BlueHat, an event last week on Microsoft's campus that allows security researchers to mingle with Microsoft developers.

"One of the messages we got was to look in the future for [our products] to not be so successful," said Pedram Amini, manager of security research at 3Com's Tipping Point division. That's because Microsoft is applying a lot of the technologies used by security researchers in-house, making the third-party techniques not as effective, he said.

For example, he said that Microsoft Office has been susceptible to fault by fuzzing, an automated technique for finding software faults when access to the code isn't available. But Microsoft has recently put more effort into using fuzzing itself, so now third-party fuzzing technologies are unlikely to be as necessary for Office 2007.

One well-known researcher who goes by the name Halvar Flake called Vista "arguably the most secure closed-source OS available on the market," in a blog post about BlueHat. "As a result I think that most of the security researchers will move on to greener pastures for a while. Why try to chase a difficult overflow out of Vista when you have Acrobat Reader installed, some antivirus software with shoddy file parsing, and the latest iTunes?"

But the security researchers don't expect to have time on their hands just because Vista and Office 2007 are more secure than their predecessors. "It's not like our industry is done now," said Dan Kaminksy, director of penetration testing services for IOActive. He pointed to weaknesses in Web-based services and technologies like virtualization.

Others agreed. "There's always something that can be improved on," Amini said. Some researcher will come up with a new approach to bug hunting or they'll focus on different technologies, he said.

While the advent of the first BlueHat event in 2005 marked a shift at Microsoft to become more open to the security research community, this BlueHat, only the second since the release of Vista, reflected another shift, Kaminsky said.

He has seen a change in Microsoft toward considering security as an engineering problem. "If you look at security as an engineering problem, then the message from the security researchers stops being 'you bad horrible people, you write bad code,' and starts becoming 'here are changes in the engineering landscape that you need to be aware of,'" he said.

That attitude change was apparent at the conference last week, he said. At some earlier BlueHats, there was some antagonism among the researchers and Microsoft employees. Kaminsky remembers a presentation at the first event that took Microsoft to task for learning about certain bugs in one piece of software and then failing to prevent the same bugs in different applications. He didn't see those types of presentations this time.

Neither did Amini. "Everyone appreciated what everyone else is doing," he said.

BlueHat typically happens twice a year, and Microsoft does not allow members of the press to attend.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.