Home > Security News > Microsoft still unlocking its security identity
Security News:
EMAIL THIS

Microsoft still unlocking its security identity

By Michael S. Mimoso, Senior Editor, Information Security magazine
15 Jun 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

WASHINGTON -- Don't hold your breath waiting for Bill Gates to iterate a vision that will realign the security market. According to research firm Gartner Inc., conflicting business interests will undoubtedly prevent Microsoft from putting itself out of business with credibility.

"There's a smelly water analogy I like to use," said Gartner analyst Neal MacDonald. "A company has all this smelly water over here and makes a fortune selling filters. Then someone says 'Eureka! I've fixed the smelly water!' And someone over here says 'No, no. We have a great business model with all these filters.

Microsoft security has improved to the point where it's not a security decision anymore [against Linux]. It's about skill sets and application and compatibility needs.
Neal MacDonald
Gartner Inc.
"There are too many conflicts of interest for Microsoft to change."

But all is not gloom and doom and potshots at Redmond coming out of last week's Gartner IT Security Summit. Security managers have noticed and applauded the progress made by the Trustworthy Computing initiative. Since Gates' famous 2002 memo that put a halt to development and product churn in favor of re-schooling programmers on secure coding and internal processes, Microsoft has been able to credibly market its security victories.

"They seem to be more interested in quality, and take more responsibility for their products' security," said Paul Scheib, CISO at Children's Hospital Boston. "When they moved to a predictable release of security patches, it made our patching much easier to manage. We have gotten good at the patch process and our security has improved."

Microsoft instituted the Secure Development Lifecycle in March 2005, a cultural and developmental change that demanded applications be put through mandatory code reviews using automated proprietary code scanners called PREfix and PREfast, along with network penetration testing and protocol fuzzing.

MacDonald said the mandatory reviews are something that Oracle Corp., Sun Microsystems Inc., SAP AG. and CA Inc. have yet to match. The results were palpable: Windows Server 2003 was the first product under the SDL, and it was widely considered much more secure than the 2001 release of Windows 2000 in terms of patches and critical vulnerabilities. The same goes for XP SP2, the first desktop product run through the SDL.

More on Microsoft security

Survey: Vista security skepticism swells

Report: Microsoft shaking up the security market

Symantec vows to fend off Microsoft

Microsoft to close security updates on old Windows

Microsoft shakeup: Nash is out

"Microsoft security has improved to the point where it's not a security decision anymore [against Linux]. It's about skill sets and application and compatibility needs. If you're looking at Apache on Linux against IIS on Windows, they're equally secure," MacDonald said. "The only downside is that [SDL] slowed things down."

Windows Vista, Microsoft's next OS, has been delayed several times and is currently scheduled for wide release in January 2007. XP SP2 and Windows Server 2003 missed their original ship dates as well.

"We value product stability more than new features," Scheib said, adding he has not beta-tested Vista and would not deploy it before the first service pack becomes available. "I don't think the slowdown in [Microsoft's] development has impacted us too greatly. Upgrading Windows across our environment is a large effort. We have plenty of other projects to get done."

Vista's selling point is security, and many expect Microsoft to heavily market the OS's bidirectional firewall offering, safer browser (IE7), Windows Services Hardening (WSH), Bitlocker encryption, USB device control, integrated Windows Defender (antispyware) and client protection. MacDonald cautions: the bidirectional firewall still lacks deep-packet inspection; WSH secures only Windows services, unlike Cisco Security Agent (Okena technology), which protects third-party apps and processes; Bitlocker requires companies also purchase Microsoft's Software Assurance maintenance program and support and plan for key management; USB protection is fine, but what about other removable media protection?

"Microsoft has to decide. Does it want to be Symantec or CA, or does it want to be a 'me-too vendor' who has good-enough products for the mid-market?" MacDonald said.

There are other technology gaps Microsoft must fill in order to be an enterprise security player. MacDonald said Microsoft must recognize enterprise heterogeneity and partner with someone who'll support Linux, Mac OS X and other platforms. It's still offering little for its mobile OS, Windows CE; there's very little behavioral protection, content filtering and monitoring. Desktop hot-patching would be appreciated, he said, as would compliance risk analysis capabilities and event monitoring and correlation.

Tags: Software Development MethodologyWindows Security: Alerts, Updates and Best PracticesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Software Development Methodology
nCircle statistics show rising Web application vulnerabilities
Common PCI questions: Web application firewalls or source code review?
Juniper pulls ATM hacking presentation from Black Hat
V.i Labs integrates Google maps to track software piracy
Software Piracy pandemic needs government role, better vendor antipiracy plans
Software piracy losses total $53 billion, study finds
Google study backs browser silent auto update feature
Secure software development starts before coding begins
Security budget issues to resonate at RSA Conference
Twitter worm attack highlights social network flaws

Windows Security: Alerts, Updates and Best Practices
When BIOS updates become malware attacks
Microsoft patches WebDAV security vulnerability in bevy of updates
Microsoft plans 10 security updates, fixing IE, Word, Excel vulnerabilities
Hackers targeting unpatched Microsoft DirectShow flaw
Microsoft warns of IIS zero-day vulnerability
Microsoft updates Office to address serious PowerPoint vulnerabilities
Microsoft to patch critical PowerPoint zero-day flaw
How to perform Microsoft Baseline Security Analyzer (MBSA) scans
Microsoft patches serious Excel zero-day, Windows flaws
Microsoft Stirling Beta 2 release includes Exchange SaaS offering

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bypass  (SearchSecurity.com)
Common Weakness Enumeration  (SearchSecurity.com)
debugging  (SearchSoftwareQuality.com)
fuzz testing  (SearchSecurity.com)
heuristics  (SearchSoftwareQuality.com)
sandbox  (SearchSecurity.com)
threat modeling  (SearchSecurity.com)
trigraph  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts