
It's not if but when, say antivirus experts...
By Tom Espiner
Published: 12 December 2006 09:10 GMT
Antivirus experts from Kaspersky Labs have predicted 90 per cent of current malware will run on Microsoft's latest operating system, Windows Vista.
Although at the moment Vista appears to be more secure than previous Windows operating systems, Kaspersky researchers warned last week that as Vista becomes more popular, it will increasingly become a target for hackers. Alexander Gostev, principal antivirus researcher for Kaspersky, said: "We're not asking whether vulnerabilities will be found but when."
According to Gostev, one of the first pieces of the operating system to be attacked will be PatchGuard, the code that protects the Vista kernel. "One of the first things to be targeted will be the technology which is meant to make getting access to the kernel more difficult," he said. "Particularly because there are already approaches for evaluating this technology."
PatchGuard, or kernel patch protection, attempts to protect the Vista kernel from unauthorised modification. It will lock down the system if it detects an unauthorised patch of certain kernel data structures or code.
In the summer, rootkit researcher Joanna Rutkowska demonstrated a signed driver requirement bypass at Defcon 2006. Hackers could try to install malware directly to the kernel using this method as drivers run in kernel space, and the signed driver requirement can be disabled fairly simply.
Another target for hackers will be the system of user privileges - User Account Control (UAC), which can be used to restrict users' administrative rights. For example, it could prevent them from downloading executable code. The probable attack vector will be Internet Explorer 7, the web browser bundled with Vista, said Gostev.
He said: "In IE 7 Microsoft fixed old vulnerabilities but new vulnerabilities are being found. Hackers and virus writers will attempt to get around user defences by exploiting the browser." He added that it is already possible to circumvent UAC.
Gostev said: "There are tens of thousands of viruses which are fully functional just under a user account. Nine out of 10 contemporary viruses will function under Vista - overall UAC will not make much difference. Users still have the right to send and receive email - hackers will program email worms."
He predicted UAC would not be popular with users anyway, as they would find it too restrictive. "Users are not going to want to work within a restrictive system. They'll disable anything which says you can't download, you can't install. There's always going to be the human factor - people always get in there and disable stuff they don't like," said Gostev.
Tom Espiner writes for ZDNet UK
Someone should give the Kaspersky pro's a medal fo...
Richard Davies
Despite recent comments regarding potential securi...
Steve Matthews, CONTEXT
Summary: Great opportunity for strong Kernel developers with experience of Linux or Windows Kernel internals, memory management, device driver ...
Software configuration management Operating system deployment and upgrade Installer and build scripting, including application installation and drive ...
Knowledge of software development in Linux is desirable, especially at a low-level such as kernel or driver development. Desirable Skills but ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Is Your Enterprise Architected for Tomorrow's Growth?
Improving IT service delivery through an integrated approach to software asset management...
TechRepublic Resource Guide: Software as a Service (SaaS) for Small and Midsize Businesses...
Download a Free Trial of SmartDraw: Learn why SmartDraw is the ideal alternative...
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead
Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy