{"id":124705,"date":"2024-09-12T18:30:26","date_gmt":"2024-09-12T18:30:26","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/09\/12\/microsoft-is-building-new-windows-security-features-to-prevent-another-crowdstrike\/"},"modified":"2024-09-12T18:30:26","modified_gmt":"2024-09-12T18:30:26","slug":"microsoft-is-building-new-windows-security-features-to-prevent-another-crowdstrike","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/09\/12\/microsoft-is-building-new-windows-security-features-to-prevent-another-crowdstrike\/","title":{"rendered":"Microsoft is building new Windows security features to prevent another CrowdStrike"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Microsoft is announcing plans to make changes to Windows that will help CrowdStrike and other security vendors operate outside of the Windows kernel. The announcement stems from a Microsoft-hosted <a href=\"https:\/\/www.theverge.com\/2024\/8\/23\/24226638\/microsoft-windows-security-summit-crowdstrike-partners\" target=\"_blank\" rel=\"noopener\">security summit<\/a> earlier this week at the company\u2019s Redmond, Washington headquarters, where it discussed changes to Windows in the wake of the disastrous CrowdStrike incident in July.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Windows kernel access has been a hot topic ever since the <a href=\"https:\/\/www.theverge.com\/2024\/7\/19\/24201717\/windows-bsod-crowdstrike-outage-issue\" target=\"_blank\" rel=\"noopener\">CrowdStrike catastrophe<\/a> took down 8.5 million Windows PCs and servers. CrowdStrike\u2019s software runs at the kernel level of Windows \u2014 the core part of an operating system that has unrestricted access to system memory and hardware. That\u2019s what allowed a faulty update to generate a Blue Screen of Death as soon as affected systems started up.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">In the months since, Microsoft has <a href=\"https:\/\/www.theverge.com\/2024\/7\/26\/24206719\/microsoft-windows-changes-crowdstrike-kernel-driver\" target=\"_blank\" rel=\"noopener\">called for changes to Windows<\/a>\u00a0to improve resiliency and dropped hints about moving security vendors out of the Windows kernel to prevent this from happening again. But there\u2019s been pressure on Microsoft, from both partners and regulators, to not move unilaterally in making that change.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Microsoft <a href=\"https:\/\/blogs.windows.com\/windowsexperience\/2024\/09\/12\/taking-steps-that-drive-resiliency-and-security-for-windows-customers\/\" target=\"_blank\" rel=\"noopener\">says it has<\/a> now \u201cdiscussed the requirements and key challenges in creating a new platform which can meet the needs of security vendors\u201d with partners like CrowdStrike, Broadcom, Sophos, and Trend Micro.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">\u201cBoth our customers and ecosystem partners have called on Microsoft to provide additional security capabilities outside of kernel mode which, along with safe deployment practices, can be used to create highly available security solutions,\u201d says David Weston, vice president of enterprise and OS security at Microsoft. <\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Microsoft has discussed performance needs and the challenges for security vendors to operate outside of kernel mode, along with the need for anti-tampering protection for security products and security sensor requirements. \u201cAs a next step, Microsoft will continue to design and develop this new platform capability with input and collaboration from ecosystem partners to achieve the goal of enhanced reliability without sacrificing security,\u201d says Weston.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">While Microsoft isn\u2019t directly saying it\u2019s going to close off access to the Windows kernel, it\u2019s clearly at the early stages of designing a security platform that can eventually move CrowdStrike and others out of the kernel. Microsoft last tried to close off access to the Windows kernel in Windows Vista in 2006, but it was met with\u00a0<a href=\"https:\/\/www.theverge.com\/2024\/7\/23\/24204196\/crowdstrike-windows-bsod-faulty-update-microsoft-responses\" target=\"_blank\" rel=\"noopener\">pushback from cybersecurity vendors<\/a>\u00a0and regulators.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">This time around, security vendors are a lot more open to it. \u201cIt was a welcome opportunity to join industry peers in an open discussion of advancements that will serve our customers by elevating the resilience and robustness of both Microsoft Windows and the endpoint security ecosystem,\u201d says Sophos CEO Joe Levy in a statement provided by Microsoft.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">\u201cI applaud Microsoft for opening its doors to continue collaborating with leading endpoint security leaders,\u201d says Kevin Simzer, chief operating officer at Trend Micro. Even CrowdStrike, the catalyst for this entire summit, was also appreciative of Microsoft\u2019s efforts. \u201cWe appreciated the opportunity to join these important discussions with Microsoft and industry peers on how best to collaborate in building a more resilient and open Windows endpoint security ecosystem that strengthens security for our mutual customers,\u201d says Drew Bagley, vice president of privacy and cyber policy at CrowdStrike.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Not everyone involved in the security world is happy about Microsoft\u2019s potential changes, though. \u201cRegulators need to be paying attention,\u201d said CloudFlare CEO Matthew Prince <a href=\"https:\/\/x.com\/eastdakota\/status\/1827004459400196237\" target=\"_blank\">on X last month<\/a>, referencing Microsoft\u2019s Windows security summit. \u201cA world where only Microsoft can provide effective endpoint security is not a more secure world.\u201d<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\"><a href=\"https:\/\/x.com\/eastdakota\/status\/1827007911396270310\" target=\"_blank\">Prince says<\/a> he\u2019s not concerned about Microsoft potentially locking down the Windows kernel, but more that the company could lock it down \u201cfor everyone else\u201d while still giving its own offering \u201cprivileged access.\u201d Microsoft also invited government officials from the US and Europe to its security summit, because it\u2019s clearly aware of concerns like Prince\u2019s.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">The summit comes right in the middle of a broader cybersecurity overhaul inside Microsoft, following years of\u00a0<a href=\"https:\/\/www.theverge.com\/2024\/4\/25\/24139914\/microsoft-cyber-security-incidents-trust-report\" target=\"_blank\" rel=\"noopener\">incidents and criticisms<\/a>. Microsoft employees are now being\u00a0<a href=\"https:\/\/www.theverge.com\/2024\/8\/5\/24213774\/microsoft-security-performance-reviews-employees-top-priority\" target=\"_blank\" rel=\"noopener\">judged directly on their security work<\/a>, with the company tying those efforts to employee performance reviews.<\/p>\n<\/div>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.theverge.com\/2024\/9\/12\/24242947\/microsoft-windows-security-kernel-access-features-crowdstrike\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft is announcing plans to make changes to Windows that will help CrowdStrike and other security vendors operate outside of the Windows kernel. The announcement stems from a Microsoft-hosted security summit earlier this week at the company\u2019s Redmond, Washington headquarters, where it discussed changes to Windows in the wake of the disastrous CrowdStrike incident in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":124706,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-124705","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/124705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=124705"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/124705\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/124706"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=124705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=124705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=124705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}