Home > Information Security Magazine > Features > Examine Security Features and Tools of Microsoft Windows Server 2008
EMAIL THIS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

Examine Security Features and Tools of Microsoft Windows Server 2008
by Beth Quinlan
Issue: Feb 2008
printer-friendly

[TABLE]

[TABLE]

[TABLE]

[TABLE]

[TABLE]

You can even specify which privileges or special powers a service can have (shutdown, audit, etc.), so malware doesn't have access to all the default privileges of the account under which the compromised service is running.

Further, services now have a unique security identifier (SID), so they can no longer run under the radar. In previous server OSes, a service would run anonymously under the context of the service account it was configured to use, such as LocalSystem, giving the service extensive privileges on the local computer. T



hat meant you could only apply an Access Control List (ACL) against the service account--generally not a practical solution--not the actual service, essentially giving administrative control to an anonymous entity. With unique SIDs, ACLs can be applied to specific services for tight control.

This can be taken a step further by applying a write-restricted token to the service process. Write attempts to resources that do not explicitly grant the service SID access will fail.

[TABLE]

[TABLE]

[TABLE]





TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts