Advertisement
Promo

Security threats Toolkit

Researcher: Operating systems inherently flawed

Tom Espiner ZDNet.co.uk

Published: 18 Sep 2007 11:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Windows, Linux and Mac operating systems are all inherently flawed due to the nature of their architecture, according to a leading security researcher.

Joanna Rutkowska said that inherent operating-system insecurity is a bigger problem than human fallibility. "Some bugs will catch everyone, even if the users are tech savvy," said Rutkowska, the chief executive of Invisible Things Labs. "The technology is as faulty as the human users, but human users can be educated."

The security researcher gave the example of exploits of Windows Vista. Vista security was bypassed in April by the .ani bug, while Vista kernel exploits were revealed at the Black Hat conference in August by Rutkowska.

She said that the weakest link in operating-system security is third-party drivers, because they can contain flaws that are not under the control of the vendor. "You can forbid changes to the registry key but, if you have, say, a buggy Wi-Fi driver, you can bypass the security technology on the operating system," said Rutkowska. "Third-party drivers are easier to attack than those of Microsoft, who have [undertaken] years of research."

The researcher advocated the concept of "microkernelisation", which is a compartmentalisation of drivers and other executable code that would only allow digitally signed code to execute on the kernel. Using the concept, drivers communicate with each other in a distributed system using "special protocols". Rutkowska suggested that microkernelisation should be combined with hardware virtualisation to create more robust architectures.

Read this

Feature
Feature: Locating the real threats to corporate security

With organised criminals seizing the opportunities of cybercrime, how accurate is the established belief that company insiders are the biggest threat to IT security?

Read more +

The researcher added that integrity checking on systems through digital certification and whitelists could solve user difficulties.

Peter Firstbrook, Gartner's research director of secure business enablement, said that Microsoft was "not interested" in microkernelisation due to the massive upheaval it would cause in rewriting code.

Phil Dunkelberger, chief executive officer of security firm PGP, said that to completely re-architecture mainframes and business operating systems would not be practical because the cost would be too great. Dunkelberger said that the largest threat to businesses was not data loss through malware, but data theft by employees.

A Deloitte survey of financial companies, released on Tuesday, also said that humans were the weakest link in terms of corporate security.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
7 out of 7 people found this useful


Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters