Windows Vista introduces numerous new security and safety features intended to deliver greater privacy, security, and system integrity than earlier releases of Microsoft Windows. In 2002 Microsoft announced its Trustworthy Computing initiative, which introduced within the corporation an ambition to build secure software by means of new development policies and procedures. New principles mandated the reviewal of software to ensure that architectures, designs, and implementations promote resilience to attacks and vulnerabilities; that default configurations promote security from the onset; that software patches are broadly distributable and securely deployable; and that straightforward security guidance is available. Windows Vista is the first Microsoft Windows operating system built in full accordance with the principles of this initiative. During its development Microsoft executives including Bill Gates and Jim Allchin cited security as being both its most important development factor and value proposition for consumers. New security features in Windows Vista include anti-malware software (Windows Defender); exploit protection features such as Address Space Layout Randomization, Data Execution Prevention improvements, and stack overflow detection for operating system binaries. Windows Firewall introduces new features such as support for IPSec, Kerberos, and outbound filtering. For privacy, Windows Vista introduces features such as Encrypting File System improvements (page file encryption and smart card support), and parental controls. For system integrity, Windows Vista introduces features such as Code Integrity for the enforcement of kernel-mode code-signing to assess the legitimacy of the boot process and of crucial system components. Windows Service Hardening reduces privileges of Windows services and limits their interactions between file system object resources, processes, and other Windows services (which was a noteworthy avenue of attack in earlier releases of Windows, with Blaster being a prominent example). There are major changes to or replacements of components that originated in earlier releases of Windows. CryptoAPI is replaced by Cryptography API: Next Generation. GINA is succeeded by Credential Providers (with refactoring in Winlogon). With the introduction of User Account Control, Windows Vista is built on the principle of least privilege. The use of NTFS for the partition on which Windows is installed is now mandatory. Mandatory Integrity Control enforces lower and higher levels of privilege across file system object resources and processes. Windows Resource Protection supersedes Windows File Protection. There are several changes to strengthen access-control lists of system directories when contrasted with previous releases of Windows. On x64-based systems kernel-mode driver signing is mandatory; unsigned software will not load and will not run. Windows Vista is the first release of Microsoft Windows with functionality based on firmware and hardware designed by the Trusted Computing Group (TCG), with native support for the TCG specification and secure cryptoprocessor, Trusted Platform Module (TPM). BitLocker Drive Encryption, a full-volume encryption feature available in Windows Vista Enterprise and Windows Vista Ultimate relies on both TCG-compliant firmware and TPM 1.2 to ensure boot integrity by sealing volume encryption secrets to an environment; if subsequent environments do not match these measurements, secrets will not be revealed, and the volume will not be decrypted. Windows Vista additionally introduces digital rights management (DRM) for commercial high-value content.
User Account Control
… excerpt ends here. Continue reading the full article.
