openPR Logo
Press release

Agnitum Analyzes Latest Microsoft Security Initiatives

08-01-2006 04:15 PM CET | IT, New Media & Software

Press release from: Agnitum ltd.

Security Experts warn of more threat to third-party security software vendors than to hackers caused by introduction of Kernel Patch Protection by Microsoft

London, 26 July 2006 – After an in-depth analysis of the new security measures introduced by Microsoft under the name “Kernel Patch Protection”, the computer security experts at Agnitum today announced that this attempt to improve security instead is a possible move to preclude or block the use of third-party security software in Windows.


Agnitum experts also believe that it will bring more difficulties to third-party security software vendors than to hackers.

Key conclusions from the analysis include:


Microsoft kernel patch protection prevents security software developers from installing security software at the kernel level, an approach that’s necessary to ensure security against malware applications.
If certain versions of the kernel are in use, kernel patch protection does not prevent hackers from reverse engineering specific areas of code in the operating system to re-acquire unauthorized access to the kernel.
If third-party security software is going to work, then independent software companies must similarly reverse-engineer access to the operating system kernel, making it more difficult to install and maintain products that ensure better security for Windows and Windows users.
“As the vendor of Outpost Firewall Pro, we have to install at the kernel level.” said Alexey Belkin, chief software architect at Agnitum. “In addressing the potential problem of not being able to install Outpost on new versions of Windows, we have discovered that it is possible to push past the new security measures introduced by Microsoft – if we use the same techniques used by hackers. That’s a wide-open hole. If we discovered it, then hackers will discover it, and they will use that hole to install malicious software.”



Kernel Patch Protection is intended to provide better protection for low-level system activities such as the file and registry operations of the Windows kernel, the deepest level of OS operations, (http://www.microsoft.com/whdc/driver/kernel/64bitpatch_FAQ.mspx). Any program that gains access to the kernel can, for instance, hide a folder on the hard disk and make it impossible to delete that folder using regular Windows tools. While malicious programs can modify the Windows kernel and hide themselves in this way to surreptitiously steal information, security software developers also need access to the kernel to provide PC security.



Forcing independent software developers down the road of acting like hackers gives the advantage to hackers, as they don’t need to undertake the level of compatibility testing and quality assurance required by legitimate software developers.



The full analysis is available on the Agnitum website: http://www.agnitum.com/r/kernel/patching/



"Microsoft made a logical move with this attempt to protect Windows against rootkits,” said Mikhail Penkovsky, vice president of Sales and Marketing at Agnitum.

“Unfortunately, it doesn’t really resolve the problem, and also makes it a great deal more difficult for independent security software developers to be fully compatible with Windows. Nobody knows if Microsoft has done this intentionally, but we can’t avoid the suspicion that this move may have been designed to force users to rely on Microsoft and only Microsoft for Windows security. If past experience is anything to go by, third-party security software solutions are likely to be more robust and provide better protection for users, who will be the biggest losers if this proves to be the case.”



In 64-bit versions of Windows and in the upcoming Windows Vista, kernel patch protection will insulate the kernel from legitimate changes. This means that no third party security software vendor will be able to install security software that uses kernel functions using legitimate coding approaches, but hackers can still feel free to reverse-engineer their way to successful rootkit delivery using less-legitimate methods.


“The problem lies in fact that these less-legitimate methods will work only for specific Windows kernel versions,” said Penkovsky. “If legitimate independent software developers are forced to take this approach, with every serious update to the OS, those developers will have to make changes to their installation methods. It will be a nightmare for legitimate developers while posing little or no problem for hackers, who don’t have to maintain 100-percent compatibility. And improvements to malware are much easier to code than improvements to security software.”


Press Contact:
Lisette Vanrykel
lvanrykel@agnitum.com
+34 93 218 55 47

Agnitum ltd.

Bolshoy Sampsonievskiy, 60, liter A

St.Petersburg, Russia, 194044

Press Contact : Lisette Vanrykel
+34 93 218 55 47

About Agnitum

Founded in 1999, Agnitum Ltd. (www.agnitum.com) is committed to delivering and supporting high-quality, easy to use security software. The company’s products are Outpost Firewall Pro, securing personal and family desktops, and Outpost Network Security, ensuring reliable endpoint protection and performance for small business networks. Agnitum firewall technology is licensed by Novell, Sophos and Lavasoft.

This release was published on openPR.

Permanent link to this press release:

Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.

You can edit or delete your press release Agnitum Analyzes Latest Microsoft Security Initiatives here

News-ID: 10407 • Views:

More Releases from Agnitum ltd.

Agnitum delivers all-round proactive protection for Windows users
Outpost Security Suite Pro defends desktops, notebooks against malware, spam, identity theft, and other Internet threats ST. PETERSBURG, RUSSIA, 2 May 2007 -- The security experts at Agnitum today delivered battle-hardened protection against malware, spam, identity theft and other Internet-borne threats to home and small-business Windows users. Available now, Outpost Security Suite Pro (OSS) is comprehensive, proactive security that combines in a single product the company’s acclaimed personal firewall, an innovative all-in-one
Agnitum licenses Outpost firewall technology to Bullguard and CAT
London, 15 November 2006 – Bullguard Ltd. and CAT today announced they are licensing award-winning Outpost firewall technology from the computer security experts at Agnitum Ltd. Bullguard (http://www.bullguard.com) specializes in user-friendly PC and mobile security, and will integrate Agnitum’s firewall engine into version 7 of the new Bullguard Internet Security Suite. CAT owns the brand Quick Heal (http://www.quickheal.com), which is India’s leading provider of anti-virus software. CAT will re-brand Outpost Firewall Pro
Independent tests identify Agnitum Outpost Firewall Pro 4.0 as the security soft …
London, 25 October 2006 – Independent tests have determined that Outpost Firewall Pro 4.0 from Agnitum is the software firewall best able to defend itself from the type of direct and brutal attacks that can cripple, disable and shut down less robust firewalls. Outpost was the only one of 13 software firewalls to pass all 38 tests conducted by Guillame Kaddouch, an expert in computer security who operates the security
Introducing Agnitum's Outpost Firewall Pro 4.0
The Ultimate in Proactive Protection for Windows PCs London, 27 September 2006 - Agnitum, Europe’s leading developer of personal firewalls and an acknowledged expert in PC security, today announces the release of the latest version of Outpost Firewall Pro, the award-winning Internet security software. Outpost Firewall Pro 4.0 offers powerful protection against spyware, keyloggers, Trojans and other malicious code, as well as protecting users’ personal information from being stolen and preventing

All 5 Releases


More Releases for Windows

Identify Hidden Opportunities of Energy Efficient Window Market | Crestline Wind …
A latest study released by HTF MI on Global Energy Efficient Window Market covering key business segments and wide scope geographies to get deep dive analysed market data. The study is a perfect balance bridging both qualitative and quantitative information of Energy Efficient Window market. The study provides historical data (i.e. Volume** & Value) from 2013 to 2018 and forecasted till 2025*. Some are the key & emerging players that
Feb 22, 2018: Soundproof Windows Market Manufacturers Milgard, Soundproof Window …
QY Research Store Recently added detailed market study on the "Global Soundproof Windows Market Research Report 2018-2025" which provides an outlook of current market value of Soundproof Windows Market as well as the expected forecast of Rate on Investment (ROI) with growing CAGR of XX% in Soundproof Windows Market by the end of 2025. The report on the global Soundproof Windows market uses the top-down and bottom-up approaches to define,
2017 Windows and Doors in Qatar with Detail - Market Value By Domestic Productio …
"Windows and Doors in Qatar to 2017: Market Databook" The Report covers current Industries Trends, Worldwide Analysis, Global Forecast, Review, Share, Size, Growth, Effect. Description- Synopsis Timetrics 'Windows and Doors in Qatar to 2017: Market Databook' contains detailed historic and forecast market value data for the windows and doors market in Qatar, including data for domestic production, supply balance, existing stock, imports and exports. Review and forecast data is included for categories of
Energy Efficient Windows Market by Glazing Type : Double Glazing Windows and Tri …
Albany, NY, 14th FEB : Nations are ramping up their efforts to reduce their carbon emissions by as much as possible in the light of the exceeding levels of pollution and resource depletion across the world. Countries such as China, the U.S., and Russia have all set environment conservation goals for their lands, aiming for as much as 40% to 45% carbon footprint reduction by 2020, as set by China.
Perle Multimodem Cards awarded Windows 8 and Windows Server 2012 certification
NASHVILLE, TN—January 24th, 2013— Perle Systems, the global developer and manufacturer of device connectivity solutions announces Windows 8 and Windows Server 2012 certification for PCI-RAS Multimodem Cards. Perle is the first company to receive 32-bit and 64-bit Windows 8 and Windows Server 2012 certification for Multimodem Cards in the industry. “Perle Systems PCI-RAS Multimodem cards provide an easy to administer dial-in/dial-out solution for remote workers and customers.” comments Julie McDaniel,
serVonic’s UC-Solutions for Windows 8 and Windows Server 2012
serVonic’s Unified Communications solutions for Windows 8 and Windows Server 2012: IXI-UMS Unified Messaging Server 5.90 and IXI-PCS Professional Call Server 1.21 as always are reliable and professional. “We have tested our software solutions with the new Microsoft operating systems extensively,” says Jochen Klein, CEO at serVonic. “As expected, the current versions of IXI-UMS and IXI-PCS – server- as well as client-side – work perfectly to the full extent.“ All