Welcome | Sign In
ECommerceTimes.com
Security

Gates Says Microsoft Security Moving Forward

Print Version
E-Mail Article
Reprints
Gates Says Microsoft Security Moving Forward

While Gates can claim some success with Microsoft's quickened security response and new, monthly security update schedule -- praised for reducing the burden of constant and confusing patches -- Microsoft's Internet Explorer continues to be an avenue of attack against Internet users.


Think you have to compromise on security to save on costs? Think Again. Trend Micro™ Enterprise Security, powered by the Trend Micro Smart Protection Network™, can lower your content security management costs by up to 40%. Find out just how much you’ll save with our TCO Impact Calculator.

Microsoft (Nasdaq: MSFT) chief software architect Bill Gates claimed this week that his company has made great security strides, responding quickly enough to the increasing threat of attackers who are now using automated techniques to strike more quickly at exposed Windows systems.

Gates pointed to improvements in the time it has taken Microsoft to respond to significant security issues, as well as improvements to defense measures that will be rolled out in the upcoming months -- primarily default enablement of the Windows XP firewall and automatic update features.

However, security analysts agreed that as far as Microsoft has come, the company has just as far to go before Windows systems are secure. During a speech in Australia, Gates sang the praises of Microsoft's efforts to screen out spam and urged the use of firewalls, saying that the Internet must be made as reliable and secure as other "utilities."

In response to this comment, Gartner (NYSE: IT) research vice president Richard Stiennon said that the Internet is far from being a utility. "It has still got an aspect of the wild west to it, with thousands of providers and no standards body to come together on how to approach things," Stiennon told TechNewsWorld.

"It's also reactive, as organizations and groups do take the appropriate action when necessary, but it's a growing, living organism and it's still going to catch colds and have rotting parts that fall off and die."

Matter of Time

Pointing to the average 100 days to fix a security hole in other operating systems, Gates claimed that Microsoft had dramatically reduced its turnaround time on Windows vulnerabilities to fewer than 48 hours.

Gates blamed lack of firewalls and strong passwords for security breaches, and said Microsoft must reduce the number of security updates for Windows to one or two per year.

However, Stiennon warned of the required testing and potential side effects of the security-focused Windows XP Service Pack 2, and said that the lack of time required for attackers to leverage exploits is worrisome.

"The concern is that the exploit will be available before Microsoft knows about it," Stiennon said. "Right now, they're relying on third parties."

"So far, the perception out there is that they're actually slow," Stiennon added, referring to Microsoft's talk of SP2 since last winter, but no announced release date.

Exploiting Explorer

While Gates can claim some success Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse with Microsoft's quickened security response and new, monthly security-update schedule -- praised for reducing the burden of a constant and confusing stream of patches -- Microsoft's Internet Explorer continues to be an avenue of attack against Internet users.

Last week, Microsoft Internet Information Services (IIS) servers were compromised to deliver malicious code to visitors of those infected sites. The Russian group's site that was spreading the code was taken down before the attack could spread significantly, but security experts expressed concern over the new tactic.

"They've developed a new trick to hit fully patched IIS boxes, and if you go to a malicious Web site, it can infect at will and it's silent," iDefense director of malicious code intelligence Ken Dunham told TechNewsWorld. "What's interesting about the IIS incident is that somehow they were able to hack into boxes of some very big companies. Nobody knows how they got into those boxes."

Huge Undertaking

Dunham said that a combination of two things -- the availability of malicious source code that allows attackers to "cut and paste" dangerous code, and the rapid escalation of vulnerabilities, particularly with Explorer -- have combined to put users and the Internet at large at greater risk.

Dunham said that last week's IIS attacks bordered on chaos. Security experts had a difficult time figuring out the attack, determining whether customers were hit and what vulnerabilities were being exploited. The security expert added that Microsoft has made efforts to improve its software, pursue attackers and strengthen defense, but more effort is needed.

"They've taken many steps in the right direction, but they have many more to take," Dunham said. "It's a huge undertaking."


Print Version E-Mail Article Reprints More by Jay Lyman


More by Jay Lyman

Open Source Developer Dumps Novell Over Microsoft Deal
December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux
December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0
December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network