Windows 10 Security Internals

Slides:



Advertisements
Similar presentations
Saurabh Bhatia Program Manager Microsoft Corporation Andrew Whitechapel Senior PM Microsoft Corporation TL01.
Advertisements

1 of 3 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
1 Julius Davies Architectural Technology Specialist Microsoft.
Msdevcon.ru#msdevcon. ИЗ ПЕРВЫХ РУК: КАК СДЕЛАТЬ ВАШ КОД БЫСТРЫМ ПРОФАЙЛИНГ КЛИЕНТСКИХ И СЕРВЕРНЫХ ПРИЛОЖЕНИЙ В VISUAL STUDIO 2012 MAXIM GOLDIN Senior.
11/12/ :06 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Volume Licensing Readiness: Level 100
Fundamentals Sunny Sharma Microsoft
Windows 10 – the safest and most secure version of Windows
5/25/2018 2:27 PM Secure Tier 2! Enhance Your Security Posture on End User Machines with Windows 10 Chris Jackson Cybersecurity Enthusiast Chief Awesomeologist,
Volume Licensing Readiness: Level 100
The changing of the guard
Windows Server 2016 Secure IaaS Microsoft Build /1/2018 4:00 AM
Journey to Microsoft Secure Cloud
Unit testing your metro style apps built using XAML
6/10/2018 5:07 PM THR2218 Deploying Windows Defender AV and more with Intune and Configuration Manager Amitai Senior Program Manager,
Mapping NIST CSF and GDPR Frameworks to Microsoft Technologies
Contain and Isolate Ransomware with Citrix and Microsoft
Tactic 4: Defend Your Domain Controllers
Learning about Containers in the Real World
Best practices to secure Windows 10 with already included features
Microsoft Edge Security with Windows Defender Application Guard
7/1/2018 5:07 PM BRK2080 Deploying and Managing Windows Defender Application Control in the Real World Nazmus Sakib Jeffrey Sutherland Dune Desormeaux.
A Fast Track into Device Guard
Getting Started with Visual Studio Tools for Tizen
Microsoft Connect /23/2018 5:27 PM
Volume Licensing Readiness: Level 100
Windows Server & Hyper-V Containers Vaggelis Kappas
Microsoft Connect /18/ :32 PM
What’s New in Windows Server 2016
Modernizing App Experiences
Device Guard: AppLocker on steroids
Newness and Coolness in Configuration MANAGER
The Microsoft 365 Powered Device
Deploy Windows 10 Mobile for the mobile workforce
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
Drop the hammer down on malware threats with Windows 10’s Device Guard
Laura A. Robinson July 10, June 30, /15/2018 4:19 PM
11/17/2018 9:32 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Protecting Against Credential Theft: Today and Tomorrow
Обзор Windows Azure Connect
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
Security in a Container based World
Microsoft Build /24/2018 2:23 PM © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY,
Microsoft Connect /26/2018 6:09 PM
Hosted Web Apps with Windows App Studio
11/27/2018 4:20 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Docker Workflows with Visual Studio
Modern Windows 10 device 12/2/2018 E3 E3 P E3 P P P P E3 E3 P P P P P
Digital display units This template is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, AS TO THE INFORMATION.
Intranet web banner units
A/B Testing for UWP Apps: Experiment for Success
Application Insights Diagnostics Preview
Enterprise Mode Overview
TechEd /6/2018 8:16 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
12/25/2018 5:11 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
What’s new in the Fall Creators Update for Windows Defender ATP
Microsoft Connect /17/2019 9:55 PM
Welcome to Azure Notebooks
Internal social media units
2/16/2019 1:48 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Microsoft Connect /23/ :38 AM
Microsoft Connect /25/2019 1:20 PM
4/12/2019 5:27 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
4/20/ :00 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
5/6/2019 7:40 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
Advanced multi-user capabilities in Dev Center
7/2/2019 8:03 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
Skype for Business Online Assessment Results
11/11/2019 1:15 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
WCL425 App Compat for Nerds Chris Jackson.
Presentation transcript:

Windows 10 Security Internals 6/10/2018 12:37 PM Windows 10 Security Internals Chris Jackson Sr. Architect, Cybersecurity © Microsoft Corporation. All rights reserved.

Isolate and Containerize Security principles Known Good Reduce Actors Trust Software by Exception Whitelist Validate Constrain Execution Assume Breach Minimize Impact Isolate and Containerize Isolation Sandboxes Contain Damage © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

Isolate and Containerize

Isolate and Containerize 6/10/2018 Isolate and Containerize SAP Outlook Edge Visual Studio Word © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

Microsoft Edge app Container Isolation 6/10/2018 Microsoft Edge app Container Isolation Isolation improvements with MS Edge + AppContainer MS Edge Multi-AC Isolation Model Addresses all previous limitations of Internet Explorer sandbox Significant attack surface reduction Flash running out-of-content process (starting in Windows 10 Anniversary Update) Edge Manager Process (AppContainer) Elevation Broker (MediumIL) Trust Boundary IPC Trust Boundary IPC Trust Boundary Edge Tab (AppContainer) Flash Content Process IPC The Microsoft Edge isolation model addresses all previously known “by-design” sandbox attacks © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

traditional platform stack 6/10/2018 traditional platform stack Device Hardware Kernel Windows Platform Services Apps © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

VIRTUALIZATION BASED SECURITY Windows 10 6/10/2018 VIRTUALIZATION BASED SECURITY Windows 10 Kernel Windows Platform Services Apps SystemContainer Trustlet #1 Trustlet #2 Trustlet #3 Hypervisor Device Hardware Windows Operating System Hyper-V © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

Trust Code by Exception

APPS Today’s challenge: Trusted by default until defined as threat 6/10/2018 Today’s challenge: Trusted by default until defined as threat Detection based methods alone can’t keep up APPS © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

Device guard in vbs environment 6/10/2018 Device guard in vbs environment decisive mitigation Kernel Windows Platform Services Apps SystemContainer DEVICE GUARD Trustlet #2 Trustlet #3 Hypervisor Device Hardware Windows Operating System Hyper-V © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

Blacklist User Writeable Areas 6/10/2018 Blacklist User Writeable Areas Program Files Windows Windows System © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

Post-Compile Mitigations 6/10/2018 Post-Compile Mitigations Administrative Templates\System\Mitigation Options\Process Mitigation Options 3 2 1 9 8 7 6 5 4 F E D C B A A Enable DEP B Enable ATL Thunk emulation for DEP C Enable SEHOP D Enable ASLR E Enable Bottom-Up ASLR Always On F Enable Bottom-Up ASLR Always Off © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

Control Flow Guard Valid jump locations 6/10/2018 Y YY © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

6/10/2018 12:37 PM © Microsoft Corporation. All rights reserved.