pwshub.com

Microsoft plans to move security software out of the Windows kernel

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

Forward-looking: The CrowdStrike incident has once again highlighted concerns about Windows security. Microsoft was adversely affected by the Texas company's poor update practices, but it prompted Redmond to address how Windows could be improved to prevent future global incidents.

CrowdStrike released a faulty update for its Falcon Sensor security software, which had widespread consequences for the entire Windows ecosystem. After assisting millions of PCs in getting back online, Microsoft promised to bolster Windows security through significant changes aimed at making the operating system more resilient.

On September 10, the company hosted a community meeting, where the initial steps to strengthen the Windows platform were shared online.

Microsoft said the Windows Endpoint Security Ecosystem Summit brought together endpoint security vendors and government officials from the US and Europe. Although no formal decisions were made, the meeting resulted in a consensus on several key points that will require further development.

The first key takeaway from the summit relates to the future of traditional software offerings. The consensus suggests that the Windows ecosystem and its customers benefit from a diverse range of security products, and this variety is unlikely to disappear anytime soon. Microsoft and its partners explored numerous opportunities for mutual growth in the short term, with the primary focus on ensuring the safety and resilience of their shared customer base.

Microsoft outlined how it is managing security through its Safe Deployment Practices and expressed its willingness to share best practices, data, tools, and "documented processes" with the community. The company explained its approach to the gradual, staged deployment of updates, which improves Windows resilience and allows for pausing or rolling back faulty updates when necessary.

During the summit's "rich discussion," Broadcom, Sophos, and Trend Micro also shared their own best practices.

In addition to SDP, Microsoft is laying the groundwork for long-term solutions to Windows' security challenges. The conversation centered on "new platform capabilities" aimed at moving security software outside of Windows kernel mode. Microsoft had attempted this with Windows Vista but faced significant pushback from antivirus vendors and regulators. Now, vendors seem more open to what Microsoft has to offer.

"Both our customers and ecosystem partners have called on Microsoft to provide additional security capabilities outside of kernel mode," the company explained.

Microsoft is reportedly developing a new platform that addresses the needs expressed by security vendors, including improved performance, anti-tampering protection, and more.

Microsoft will continue designing and developing this platform with input from its ecosystem partners, with the goal of improving reliability without compromising security. In the meantime, customers are encouraged to adopt the vendor-neutral best practices Microsoft shared a few months ago to mitigate issues when the next faulty security update occurs.

Source: techspot.com

Related stories
1 month ago - Now there's an idea – parsing config data in user mode Updated  Microsoft has vowed to reduce cybersecurity vendors' reliance on kernel-mode code, which was at the heart of the CrowdStrike super-snafu this month.…
1 month ago - Remember the buzz back in June about Microsoft's new artificial intelligence-powered automatic screenshotting feature, Windows Recall? On Wednesday,...
3 weeks ago - Cracked Labs examines how workplace surveillance turns workers into suspects Software designed to address legitimate business concerns about cyber security and compliance treats employees as threats, normalizing intrusive surveillance in...
1 month ago - Now that's a TRACTOR pull request To accelerate the transition to memory safe programming languages, the US Defense Advanced Research Projects Agency (DARPA) is driving the development of TRACTOR, a programmatic code conversion vehicle.…
6 days ago - Some users will see the appeal of Big Red stacking its hardware in Amazon's datacenters Analysis At Big Red's recent CloudWorld shindig in Las Vegas, Matt Garman, CEO of AWS, looked comfortable and relaxed being hosted by arch rival...
Other stories
22 minutes ago - After California passed laws cracking down on AI-generated deepfakes of election-related content, a popular conservative influencer promptly sued,...
45 minutes ago - Act fast to grab this high-performing mesh router for less than $500, keeping you connected while saving some cash too.
45 minutes ago - If the old-school PlayStation is dear to your heart, you can soon relive those totally sweet 1990s memories. Sony is releasing a series of products...
46 minutes ago - If you've got an old phone to part with, T-Mobile is offering both new and existing customers the brand-new Apple iPhone 16 Pro for free with this trade-in deal.
46 minutes ago - Who doesn't want the best for their beloved pooch? Grab some of these tasty treats to make your dog feel special.