Internet Explorer 7 Security Features Steve Lamb Technical Security Microsoft Ltd

Slides:



Advertisements
Similar presentations
IEs Protected Mode in Windows Vista TM January 20, 2006 Marc Silbey Program Manager.
Advertisements

Why should my organisation move to Internet Explorer 9? An upgrade guide for IT professionals.
Microsoft ® Office 2007 Training Security II: Turn off the Message Bar and run code safely P J Human Resources Pte Ltd presents:
Lesson 10: Starting Windows Applications start an application program move between open application programs start an application using the Run command.
Microsoft Windows XP SP2 Urs P. Küderli Strategic Security Advisor Microsoft Schweiz GmbH.
Configuring Windows Internet Explorer 7 Security Lesson 5.
Connect with life Gopikrishna Kannan Program Manager | Microsoft Corporation
Configuring Windows Vista Security Chapter 3. IE7 Pop-up Blocker Pop-up Blocker prevents annoying and sometimes unsafe pop-ups from web sites Can block.
Chapter 9: Configuring Internet Explorer. Internet Explorer Usability Features Reorganized user interface Instant Search box RSS support Tabbed browsing.
This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation. All.
The New Internet Explorer 7 By Ronald Pastor. Overview  Makes everyday web surfing easier –Internet Explorer 7 provides improved navigation through tabbed.
Optimizing Client Security by Using Windows Vista.
Information for Developers Windows XP Service Pack 2 Information for Developers.
1 of 7 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
April-June 2006 Windows Hosting Seminar Series Product Roadmap: IIS 7.0 Matthew Boettcher Web Platform Technical Evangelist (Hosting) Developer & Platform.
Internet Explorer Opportunities For Partners Margaret Cobb Product Manager IE Group Microsoft Corporation.
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
Internet Explorer Today & Tomorrow Margaret Cobb Internet Explorer Product Manager Windows Client Group microsoft.com Microsoft Corporation.
Cyra Richardson Microsoft Corporation Internet Explorer 7.
Microsoft ® Official Course Module 9 Configuring Applications.
PowerPoint Presentation to Accompany GO! with Internet Explorer 9 Getting Started Chapter 3 Exploring the World Wide Web with Internet Explorer 9.
With Internet Explorer 9 Getting Started© 2013 Pearson Education, Inc. Publishing as Prentice Hall1 Exploring the World Wide Web with Internet Explorer.
Working with Applications Lesson 7. Objectives Administer Internet Explorer Secure Internet Explorer Configure Application Compatibility Configure Application.
Networks worms Denial of Service Phishing / Social Engineering BotnetsRootkits Technically-oriented social engineering attacks Cross-device attacks.
OFC 322 Building Office Research Web Services: Exposing Corporate Data Through Office Brian Jones Program Manager Authoring Services Martin Sawicki Lead.
1 What’s New In Internet Explorer 7? Chris Wilson PRS203 Group Program Manager, IE Platform & Security Microsoft Corporation.
Information for Developers Windows XP Service Pack 2 Information for Developers Tony Goodhew Product manager Developer Division Microsoft Corp
Configuring and Troubleshooting Internet Access Chapter 9 powered by dj.
Crystal Hoyer Program Manager IIS Team Preview of features that will be announced at MIX09 Please do not blog, take pictures or video of session.
Using the WDK for Windows Logo and Signature Testing Craig Rowland Program Manager Windows Driver Kits Microsoft Corporation.
Threat Management Gateway 2010 Questo sconosciuto? …ancora per poco! Manuela Polcaro Security Advisor.
MCTS GUIDE TO MICROSOFT WINDOWS 7 Chapter 9 User Productivity Tools.
Windows Vista Security Center Chapter 5(WV): Protecting Your Computer 9/17/20151Instructor: Shilpa Phanse.
COMPREHENSIVE Windows Tutorial 5 Protecting Your Computer.
Virtual techdays INDIA │ 9-11 February 2011 Security Discussion: Ask the Experts M.S.Anand │ MTC Technology Specialist │ Microsoft Corporation Anirudh.
®® Microsoft Windows 7 Windows Tutorial 5 Protecting Your Computer.
Troubleshooting Windows Vista Security Chapter 4.
Chapter 3 (HW02) Exploring the World Wide Web with Internet Explorer 9.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
1 © 2004, Cisco Systems, Inc. All rights reserved. CISCO CONFIDENTIAL Using Internet Explorer 7.0 to Access Cisco Unity 5.0(1) Web Interfaces Unity 5.0(1)
OFC335 Microsoft Office Word 2007 XML Programmability: True Data/View Separation and Rich Eventing for Custom XML Tristan Davis Program Manager Microsoft.
OFC290 Information Rights Management in Microsoft Office 2003 Lauren Antonoff Group Program Manager.
Module 5: Configuring Internet Explorer and Supporting Applications.
Microsoft Office SharePoint Server 2007 Enterprise Search Enterprise Search Overview.
Copyright ©2015 WatchGuard Technologies, Inc. All Rights Reserved WatchGuard Training WatchGuard XCS What’s New in version 10.1.
IE Security: Past, Present, and Future Tony Chor Group Program Manager Rob Franco Lead Program Manager Internet Explorer Microsoft Corporation.
MCTS GUIDE TO MICROSOFT WINDOWS 7 Chapter 9 User Productivity Tools.
1 Trustworthy Browsing Ian Moulster Software + Services Lead Microsoft Ltd.
The 2007 Microsoft Office System Servers Enterprise Content Management, Workflow and Forms Martin Parry Developer and Platform Group, Microsoft Ltd
Pete LePage Senior Product Manager Microsoft Corporation WUX310.
1 Whats New in Internet Explorer 8? Ranjana Jain IT Pro Evangelist Microsoft India MCSE, MCT, RHCE, CIW Security Analyst, CISSP.
Internet Explorer 7 Updated Advice for the NHS 04 February 2008 Version 1.3.
Return to the PC Security web page Lesson 4: Increasing Web Browser Security.
Windows Server 2003 SP1 Technical Overview John Howard, IT Pro Evangelist, Microsoft UK
DEV221 Windows Forms in Visual Studio 2005: An Overview Saurabh Pant Program Manager Microsoft Corporation.
Securing Tomorrow’s World Microsoft Security Roadmap Ed Gibson & Steve Lamb Microsoft Ltd.
Kaspersky Small Office Security INTRODUCING New for 2014!
ITMT Windows 7 Configuration Chapter 7 – Working with Applications.
Building Complete Web Application Using ASP.NET 3.5 & Visual Studio 2008 Omar Khan Group Program Manager Visual Studio.
TLA404 - MFC Updates for Visual Studio 2008 and Beyond Ale Contenti VC++ Libraries Dev Lead.
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
Windows Vista Configuration MCTS : Internet Explorer 7.0.
Windows Tutorial 5 Protecting Your Computer
Microsoft Office SharePoint Server 2007 Enterprise Search
Secure Software Confidentiality Integrity Data Security Authentication
Lesson #8 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 8 Configuring Applications and Internet Explorer.
Implementing Client Security on Windows 2000 and Windows XP Level 150
Windows Vista Inside Out
Using Software Restriction Policies
Chapter 9: Configuring Internet Explorer
Presentation transcript:

Internet Explorer 7 Security Features Steve Lamb Technical Security Microsoft Ltd

Agenda Lessons learned from IE in Windows XP SP2 Overview of Internet Explorer 7 Detailed features and demo Timeline More information

First, Let me ask… How many of you are using IE7 now? What build? How can we help you?

Post Windows XP SP2 Strengths Big security investments were worthwhile Right balance of application compatibility and security Opportunities to improve Social attacks (phishing) as important as code execution Bad trust decisions don ’ t have an “ undo ” option Make life better for Web developers Everyone wants new features

Internet Explorer 7 Major innovations in IE7 for Windows XP SP2 Enhanced functionality in IE7 in Windows Vista includes: Protected Mode Parental Controls integration Key areas of focus: Makes everyday tasks easier Dynamic security protection Improved platform and manageability

IE7 – New Look

Tabbed Browsing

Quick Tabs

Page Zoom Before After

Shrink-To-Fit Printing Web Pages Automatically Formatted To Print Properly

Inline Search

RSS Feed Platform Automatic Delivery Of Personalized Information Windows Supports RSS Feeds in Three Ways – Discover, subscribe & read as you browse – Update all feeds with a single click – Provides Common Feed List and Feed Store to enable any application to easily support RSS – Enables new scenarios via Simple List Extensions, giving RSS feeds the power to do moreBrowsersReadersAppsWebsites

RSS Feed Reader

Enhanced Validation Certificates Clearer information about trusted sites Trust Badge rotates to show Certificate Authority

15 Dynamic Security Protection Internet Explorer 7 Technology to protect against technology attacks Limit programmatic access Reduce attack surface Warn if settings insecure Simplified architecture Technology to protect against social attacks Anti-phishing service Secure site visuals and info Address bar anti-spoofing “One-click cleanup”

Security Features Protecting the machine from technology attacks Unified URL parsing Cross-domain security enhancements Code quality improvements to reduce buffer overruns ActiveX Opt-in Protected Mode (Microsoft Windows Vista only) Protecting the user from social attacks Download scanning with Windows Defender Phishing Filter High-assurance SSL and address bar Dangerous settings notification Secure defaults for International Domain Names Parental controls (Windows Vista only)

ActiveX Opt-in & Protected Mode Defending systems from malicious attack ActiveX Opt-in: puts users in control Most controls disabled Reduces attack surface Retain ActiveX benefits, increase user security Protected Mode*: reduces severity of threats IE process ‘sandboxed’ to protect OS Eliminates silent malware install Designed for security and compatibility ActiveX Opt-in Enabled Controls Windows Disabled Controls User Action Protected Mode User Action IE Cache My Computer (C:) Broker Process Low Rights * Windows Vista only

Change Settings, Download a Picture Exploit can install MALWARE IExplore.exe Install an ActiveX control Cache Web content Exploit can install MALWARE Admin Rights Access User Rights Access Temp Internet Files HKLM Program Files HKCU My Documents Startup Folder Untrusted files and settings Internet Explorer Running with Full Privileges

ProtectedMode Internet Explorer Install an ActiveX control Change settings, Save a picture Integrity Control Broker Process Redirected settings and files Compat Redirector Cache Web content Admin Rights Access User Rights Access Temp Internet Files HKLMHKCR Program Files HKCU My Documents Startup Folder Untrusted files and settings Broker Process Protected Mode Runs with Lowest Privilege

20 Security Status Bar Makes users aware of online security and privacy Enhanced Validation Standard Security Phishing Filter (Warn) Trusted party has provided extensive verification for the authenticity of certificate holder Website provided a certificate matching the server and appears trustworthy The website contains characteristics found in phishing websites … proceed cautiously Incorrect Data There are errors in the certificate provided and the website should not be trusted Phishing Filter (Block) A warning is displayed and users are navigated away from the website

IEAPFLTR.DAT Known Good URLs Phishing Filter Client-side heuristics, allow-list, and Web service URL Reputation Service

Phishing Filter Populating the URL reputation service End User Report Grader Confirmed Sites Site Owner Report Third Party Phishing databases URL Reputation Service

Address Bar Everywhere

Fix My Settings

IDN Display

Phishing Filter – Suspicious Site

Phishing Filter - Blocked Site

Fix My Settings

Customer Call To Action Read the technology overview Upgrade to IE7 RTM Test LOB applications and public websites Provide feedback to Microsoft

More IE7 Information Download the IE7 RC1 at Technical docs on IE Developer Center IT Administrator information on Technet ol/IE/ieak7 ol/IE/ieak7 More technical information on TechNet ol/IE ol/IE Follow the IE Team Blog at

Resources 1 Internet Explorer Blog Internet Explorer Feedback Alias Internet Explorer Developer Center Internet Explorer 7 Readiness Toolkit Internet Explorer 7 App Compat Toolkit Internet Explorer 7 External Bug Database Internet Explorer Administration Kit (IEAK) 7 Beta 2

Resources 2 Technical Chats and Webcasts Microsoft Learning and Certification MSDN & TechNet Virtual Labs Newsgroups communities/newsgroups/en-us/default.aspx Technical Community Sites User Groups

© 2006 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary. Steve Lamb Technical Security Microsoft Ltd