You are here: silicon.com > Software > Security Strategy

Security Strategy

Hackers 'will crack Windows security tech soon'

Expect a break in after Vista's release, says security expert...

Tags: windows vista, vista, hackers, security

By Joris Evers

Published: 13 October 2006 09:15 BST

PatchGuard, a Microsoft technology to protect key parts of Windows, will be hacked sooner rather than later, a security expert said on Thursday.

Hackers will break through the protection mechanism soon after Microsoft releases Windows Vista, Aleksander Czarnowski, a technologist at Polish security company Avet Information and Network Security, said in a presentation at the Virus Bulletin event in Montreal.

Czarnowski said: "It will probably take a year or so for it to surface publicly but I believe it will be broken earlier. PatchGuard will be broken pretty soon after the final version is released... A lot of people who would break it will probably not make it public immediately."

Microsoft designed PatchGuard - also called kernel patch protection - to safeguard the Windows kernel against malicious code attacks. Cyber crooks have found ways to exploit the innards of Windows for malicious purposes, making the protection offered by PatchGuard key to securing the operating system, Microsoft has said.

The technology applies only to 64-bit versions of Windows and debuted last year in Windows XP x64 Edition. However, while that Windows version was never broadly adopted, PatchGuard is set to become used more widely, when Vista hits store shelves in January and people are expected to buy PCs with 64-bit processors and 64-bit versions of the operating system.

Stephen Toulouse, a program manager in Microsoft's Security Technology Unit, wrote on his blog last week: "Kernel patch protection is not a silver bullet. We're not saying no one will ever crack it. The point is that the situation as it exists now… attackers don't need to do any work to access the kernel at the highest level. At least with kernel patch protection, we're trying to prevent that."

There have been some claims that PatchGuard has already been compromised but Microsoft has denied this. Toulouse wrote: "We're not aware as of right now that people have circumvented it."

If PatchGuard is ever circumvented, Microsoft would fix the issue with a software update, Toulouse wrote. "Kernel patch protection can become more resilient over time due to the combination of hardware and software advancements," he added.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Senior Windows Engineer server 2003-2008 Investment banking city based

Senior windows engineer: My client is seeking to bring on an experienced engineer who has worked on the windows platform in a large, global ...

3rd Line Support (Windows Server 2003, Windows XP, MS Exchange, AD)

I am looking for a 3rd Line Support Engineer for a contract role in Southampton, Hampshire. To be considered for this opportunity you must be able to ...

Environment Engineer

Other activities would include booking and scheduling rig usage, ensuring all Government Furnished Equipment remains traceable and ensuring currency ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: