ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Windows PatchGuard expected to be hacked soon

Joris Evers CNET News.com

Published: 13 Oct 2006 10:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

PatchGuard, a Microsoft technology to protect key parts of Windows, will be hacked sooner rather than later, a security expert said on Thursday.

Hackers will break through the protection mechanism soon after Microsoft releases Windows Vista, Aleksander Czarnowski, a technologist at Polish security company AVET Information and Network Security, said in a presentation at the Virus Bulletin event.

"It will probably take a year or so for it to surface publicly, but I believe it will be broken earlier," Czarnowski said. "PatchGuard will be broken pretty soon after the final version is released... A lot of people who would break it will probably not make it public immediately."

Microsoft designed PatchGuard, also called kernel patch protection, to safeguard the Windows kernel against malicious code attacks. Cybercrooks have found ways to exploit the innards of Windows for malicious purposes, making the protection offered by PatchGuard key to securing the operating system, Microsoft has said. (A paper on PatchGuard is available on Microsoft's Web site.)

The technology applies only to 64-bit versions of Windows and debuted last year in Windows XP x64 Edition. However, while that Windows version was never broadly adopted, PatchGuard is set to become used more widely, when Vista hits store shelves in January and people are expected to buy PCs with 64-bit processors and 64-bit versions of the operating system.

"Kernel patch protection is not a silver bullet. We're not saying no one will ever crack it," Stephen Toulouse, a program manager in Microsoft's Security Technology Unit, wrote on his blog last week. "The point is the situation as it exists now… attackers don't need to do any work to access the kernel at the highest level. At least with kernel patch protection, we're trying to prevent that."

There have been some claims that PatchGuard has already been compromised, but according to Microsoft it has not yet been hacked. "We're not aware as of right now that people have circumvented it," Toulouse wrote.

If PatchGuard is ever circumvented, Microsoft would fix the issue with a software update, Toulouse wrote. "Kernel patch protection can become more resilient over time due to the combination of hardware and software advancements," he wrote.

Security companies have been taking all sorts of shots at Vista. Symantec, the world's largest maker of antivirus software, has been leading the pack, closely followed by others including McAfee, Check Point Software Technologies and Panda Software.

Security companies have complained that PatchGuard, while meant to lock out bad guys, also prevents certain types of security software from running. The security software makers had become used to taking advantage of the Windows kernel, a move Microsoft is preventing with PatchGuard.

Tensions are flying high in the security space after Microsoft, with its $34bn war chest, entered the market. It launched Windows Live OneCare for consumers and is readying enterprise security products. Microsoft, with its huge presence on desktops, has a built-in advantage — an advantage that's making security firms nervous.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
349 out of 510 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

IT Technical Support Analyst, Windows XP, Vista, Office

IT Technical Support Analyst required with strong Windows XP/Vista and Microsoft Office experience to provide a temporary additional resource to ...

3rd Line Support (Windows Server 2003, Windows XP, MS Exchange, AD)

I am looking for a 3rd Line Support Engineer for a contract role in Southampton, Hampshire. To be considered for this opportunity you must be able to ...

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS, - Lambeth - 2198 RM helps to push the boundaries of technology to ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments