TechCrunch News 2024年11月19日
Microsoft beefs up Windows security with new recovery and patching features
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

继7月CrowdStrike故障事件后,微软承诺改进Windows安全,并于Microsoft Ignite 2024大会上宣布了一系列安全增强措施。这些措施包括计划于2025年初推出的快速机器恢复功能,允许IT管理员远程修复软件问题;将安全软件运行模式移出内核模式,降低内核崩溃风险;以及管理员保护功能,允许普通用户在需要时获得临时管理员权限,提升系统安全性。此外,微软还引入了热补丁功能,简化系统更新过程。这些举措旨在解决CrowdStrike事件暴露出的安全漏洞,并应对来自政府和公众的压力,表明微软已将网络安全提升至公司优先级。

🤔 **快速机器恢复(Quick Machine Recovery)**:计划于2025年初推出,允许IT管理员远程修复软件问题,即使Windows机器无法启动也能进行操作,提升系统恢复能力。

🛡️ **安全软件运行模式变更**: 将安全产品(如防病毒软件)的运行模式从内核模式转移到用户模式,降低内核崩溃风险,解决CrowdStrike事件的根本原因。计划于2025年7月进行私有预览。

🔑 **管理员保护(Administrator Protection)**: 允许没有管理员权限的用户在需要时获得临时管理员权限,并在任务完成后立即撤销,提升系统安全,避免攻击者直接访问内核。

🔄 **热补丁(Hot-patching)**: 在Windows 11 Enterprise 24H2和Windows 365中引入预览版,允许在后台下载并立即应用更新,无需重启设备,减少用户延迟更新的可能性,提升系统更新效率。

🧑‍💼 **加强安全团队建设**: 微软已将网络安全提升至公司优先级,投入34000名全职工程师,并将其纳入员工绩效考核,同时任命了多个产品部门的副首席信息安全官,进一步提升安全团队实力。

In the aftermath of the devastating CrowdStrike outage this July, Microsoft vowed to do better even though it insisted that the event was an aberration.

Evidently unwilling to take chances (or risk further hits to its credibility), the company on Tuesday, during Microsoft Ignite 2024, shared how it’s making changes to Windows to prevent similar incidents.

Many of those changes won’t come into force for some time.

A new capability launching in early 2025, Quick Machine Recovery, will allow IT admins to remotely make certain software fixes even when Windows machines aren’t able to boot. Microsoft says it’s also testing a way to let security products like antivirus software run outside of “kernel mode,” which means they’ll be able to run similar to most Windows applications.

The kernel mode change, scheduled to launch in private preview in July 2025, addresses the root cause of the CrowdStrike outage. A faulty update to CrowdStrike’s Falcon software caused an issue with the Windows kernel, the core of the Windows operating system — causing affected machines to crash.

“This change will help security developers provide a high level of security [and] easier recovery, and there will be less impact to Windows in the event of a crash or mistake,” David Weston, Microsoft VP of enterprise and OS security, wrote in a blog post shared with TechCrunch.

Microsoft is also previewing Administrator Protection, a feature that will let Windows users without administrator permissions make system changes on their PCs when needed. Administrator Protection creates a temporary, isolated token that grants users administrator privileges, and once the user completes their task, immediately destroys the token, Microsoft said.

The prompt users see for Administrator Protection. Image Credits:Microsoft

“With Administrator Protection, if a system change requires administrator rights, like some app installations, the user is prompted to securely authorize the change using Windows Hello,” Weston explained in the post. (Windows Hello is Windows’ biometric authentication system).

“It will also be disruptive to attackers as they no longer have automatic, direct access to the kernel or other critical system security without specific authorization,” he wrote.

At the IT management level, Microsoft is introducing hot-patching in preview for Windows 11 Enterprise 24H2 and Windows 365. Hot-patching involves downloading updates in the background and applying them immediately, eliminating the need for a device restart (and making users less likely to postpone them).

Microsoft is under intense scrutiny not only over its handling of the CrowdStrike incident, it’s also under pressure for failing to to stop hackers with links to China and Russia breach of its internal systems. U.S. government agencies have described Microsoft’s corporate culture as one that deprioritized security investments and risk management.

Microsoft CEO Satya Nadella has claimed that security is now Microsoft’s top priority. The equivalent of 34,000 full-time engineers are revamping the company’s cybersecurity practices, the company said, and every employee is now being judged on their security contributions after Microsoft tied security efforts to regular performance reviews. It has also named more than a dozen deputy chief information security officers to serve in its product groups.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Windows安全 CrowdStrike 内核模式 热补丁 网络安全
相关文章