Securing Tomorrow’s World Microsoft Security Roadmap Ed Gibson & Steve Lamb Microsoft Ltd
Security Development Lifecycle Security Response Center Better Updates And Tools
A secure platform strengthened by security products, services and guidance to help keep customers safe Excellence in fundamentals Security innovations Scenario-based content and tools Authoritative incident response Awareness and education Collaboration and partnership
Microsoft Baseline Security Analyzer 2.0 Microsoft Update Automatic Updates
Social Engineering Protections Phishing Filter and Colored Address Bar Dangerous Settings Notification Secure defaults for IDN Protection from Exploits Unified URL Parsing Code quality improvements (SDLC) ActiveX Opt-in Protected Mode to prevent malicious software Internet Explorer 7
Run More Securely Least Privilege User Account Control Anti-Phishing and IE Protected Mode - protection from unknown vulnerabilities! Windows Service Hardening Run More Securely Least Privilege User Account Control Anti-Phishing and IE Protected Mode - protection from unknown vulnerabilities! Windows Service Hardening Communicate More Securely Network Access Protection Firewall/IPsec Integration EFS support for Smart Cards Communicate More Securely Network Access Protection Firewall/IPsec Integration EFS support for Smart Cards Stay More Secure Anti-malware Restart Manager Client-based Security Scan Agent Control over device installation Stay More Secure Anti-malware Restart Manager Client-based Security Scan Agent Control over device installation Start More Securely BitLocker - Full Volume Encryption - Secure Startup - Trusted Platform Module Code Integrity Start More Securely BitLocker - Full Volume Encryption - Secure Startup - Trusted Platform Module Code Integrity Windows Vista - Integrated flexible security
Requesting access. Here’s my new health status. Network Access Protection Walk-through NetworkPolicyServer Client NetworkAccessDevice (DHCP, VPN) RemediationServers May I have access? Here’s my current health status. Should this client be restricted based on its health? Ongoing policy updates to Network Policy Server You are given restricted access until fix-up. Can I have updates? Here you go. According to policy, the client is not up to date. Quarantine client, request it to update. Corporate Network Restricted Network Client is granted access to full intranet. System Health Servers According to policy, the client is up to date. Grant access.
Service Pack 2 More than 275 million copies distributed 15 times less likely to be infected by malware Significantly fewer important & critical vulnerabilities Malicious Software Removal Tool 2.4B total executions; 230M per month Focus on most prevalent malware Dramatically reduced the # of Bot infections Most popular download in Microsoft history Helps protect more than 25 million customers Great feedback from SpyNet participants As of February 2006 Security configuration wizard More secure by design; more secure by default More than 4.7 million downloads Service Pack 1
© 2005 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.
Reference Material
Identity Access Windows Server 2003 Federation Services Certificate Services Smart Card Support Microsoft Identity Integration Server 2003 Windows Server 2003 Active Directory with Group Policy Authorization Manager VPN Access Windows “Longhorn” Server Microsoft Identity Integration Services “Gemini” Microsoft Certificate Lifecycle Manager NextGen Active Directory Windows Vista Authorization Manager Enhancements Windows Communication Foundation Information Protection Encrypted File System Windows Rights Management Services Data Protection Manager 2006 Windows “Longhorn” Server Active Directory Rights Management Services Improved smart card support “WinFX” “InfoCard” Windows Vista BitLocker RMS Client EFS Improvements Windows Presentation Foundation “XPS” Windows “Longhorn” Server NextGen Access Policy Mgmt Solutions Identity & Access Control
Roadmap Services Platform Products Frontbridge hosted services for anti-virus and anti-spam filtering (for businesses) ISA Server 2004 Sybari Antigen anti- spam and anti-virus for , IM and SharePoint Windows XPSP2 Windows Server 2003 SP1 Anti-malware tools Microsoft Update Windows Server Update Services Windows Live OneCare (for consumers) Microsoft Client Protection Microsoft Antigen Anti-virus and Anti-spam for messaging and collaboration servers ISA Server 2006 Windows AntiSpyware Windows Vista Firewall Services Hardening Next generation of services Content filtering services Next generation of security products Network Access Protection IPSec Enhancements Audit Collection Services Threat & Vulnerability Mitigation
Next Generation Security and Compliance Identity & Access Control Threat & Vulnerability Mitigation Enable secure access to information Protect against malware and intrusions Code Integrity IE Protected Mode Windows Defender IPSEC/Firewall integration Network Access Protection User Account Control Plug and Play Smartcards Granular auditing Simplified Logon architecture Fundamentals Security Development Lifecycle Threat Modeling Code Scanning Service Hardening Information Protection BitLocker Drive Encryption EFS Smartcard key storage RMS client Control over removable device installation XPS Document + WPF APIs Engineered for the future
© 2006 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS SUMMARY.