查看: 4504|回复: 4
收起左侧

[一般话题] Microsoft Active Protection Service的威力,云如何保护你的企业【转载】

[复制链接]
驭龙
发表于 2015-1-23 11:26:39 | 显示全部楼层 |阅读模式
这篇文章不错,大家看看吧

Malware can easily send a huge enterprise infrastructure into a tailspin. However, you can get greater protection from malware by using services in the cloud.

Yes, there’s an opportunity to get real-time results from suspicious malware triggers where your system can:

  • Consult the cloud upon detecting suspicious malware behaviors.
  • Respond by blocking malware based on derived logic from the account ecosystem data, and local signals from the client.
How? Through the Microsoft Active Protection Service (MAPS).


What is MAPS?

The Microsoft Active Protection Service is the cloud service that enables:

  • Clients to report key telemetry events and suspicious malware queries to the cloud
  • Cloud to provide real-time blocking responses back to the client
The MAPS service is available for all Microsoft's antivirus products and services, including:

  • Microsoft Forefront Endpoint Protection
  • Microsoft Security Essentials
  • System Center Endpoint Protection
  • Windows Defender on Windows 8 and later versions

What can MAPS do for your enterprise software security?

Enabling MAPS in your system gives you:

  • Greater malware protection through cloud-delivered malware-blocking decisions
Enable MAPS to trigger cloud calls for suspicious events. Doing so helps ensure that the machine uses the latest malware information available from the Microsoft Malware Protection Center (MMPC) research team, back-end big data, and machine learning logic.

  • Aggregated protection telemetry

    Leverage the latest ecosystem-wide detection techniques offered through the cloud. Microsoft aggregates protection telemetry from over one billion clients, and cross-references them with numerous signals.
MMPC threat intelligence leverages algorithms to construct and manage a view of threats in the ecosystem. When the endpoint product encounters suspicious activities, it can consult the cloud for real-time analysis before acting on it.

The vast data and computing resources available in the cloud allows the fast detection of polymorphic and emerging threats and the application of advanced protection techniques.

At a high level, here's what the MAPS protection looks like:



Figure 1: How the cloud protection and telemetry works from the endpoint and back.


Client machines selectively send telemetry in real-time (for detection), or periodically (for health checks) to the Microsoft Malware Protection Center’s (MMPC) cloud service which includes:

  • Threat telemetry –  to identify the threats, threat-related resources, and remediation results
  • Suspicious behavior – to collect samples, determine what to monitor and remediate
  • Heartbeat – to check the system's pulse to know if the antivirus application is still running, and if it has the updated version
The MMPC cloud service responds to client telemetry with:

  • Cloud actions – which include context and a set of instructions from the cloud on how to handle a potential threat (for example, block it).
  • Cloud false positive mitigation response – to suppress false positive malware detections
The data gathered is treated with confidentiality. See the Microsoft System Center 2012 Endpoint Protection Privacy Statement for details. To help protect your privacy, reports are sent to Microsoft over an encrypted connection. Relevant data is analyzed.

What the data shows



Figure 2: Percentage of protection MAPS can contribute over a six-month period

If we take the System Center Endpoint Protection data as an example, you'll see how MAPS is contributing 10% of protection to enterprise users on SCEP systems.

Imagine living without it – there'll be 10% more machines infected, and 10% more chance of intruders.


Prerequisites
Both Basic membership and Advanced membership enable cloud protection. See the Microsoft Active Protection Service (MAPS) section of the Microsoft System Center 2012 Endpoint Protection Privacy Statement for details.

By default, MAPS Basic is enabled in all of Microsoft’s new antimalware products. For enterprise customers, you have to enable it to get cloud protection from new threats that are coming in.

With the Advanced membership, you can get more information about the malware and/or suspicious behaviour. Such information can give your enterprise infrastructure better protection.

To get your system ready for MAPS, see the Introduction to Endpoint Protection in Configuration Manager.


So, what can you do to protect your enterprise?

Keep MAPS enabled on your system.

Join the Microsoft Active Protection Service Community.

To check if MAPS is enabled in your Microsoft security product, select Settings and then select MAPS:



Figure 3: With the MAPS option enabled, Microsoft anti-malware security product can take full advantage of Microsoft's cloud protection service

评分

参与人数 1人气 +1 收起 理由
哀酱俏佳人 + 1 版区有你更精彩: )

查看全部评分

仙乐斯
发表于 2015-1-23 12:11:11 | 显示全部楼层
谢谢龙大
哀酱俏佳人
发表于 2015-1-23 13:12:24 | 显示全部楼层
支持支持
白露为霜
发表于 2015-1-23 15:39:21 来自手机 | 显示全部楼层
恶意软件可以很容易地把一个巨大的企业基础设施陷入一片混乱。然而,你可以通过使用的云服务从恶意软件更多的保护。
是的,有机会从可疑的恶意软件获得实时结果触发你的系统:
*请云在可疑的恶意软件行为检测。
*回应阻断基于派生逻辑从账户系统数据的恶意软件,从客户端的本地信号。
如何?通过微软主动保护服务(图)。
什么是地图吗?
在微软主动保护服务是云服务,使:
*客户报告关键事件和可疑的恶意软件遥测查询云
*云提供实时阻断响应返回给客户端
可用于所有微软的杀毒产品和服务是地图服务,包括:
*微软的Forefront端点保护
*微软安全要点
*系统中心的端点保护
* Windows Defender对Windows 8和以后的版本
有什么可以做为你的企业地图软件安全?
在你的系统使地图给你:
*更高的恶意软件保护通过云交付阻止恶意程序的决定
使地图触发可疑事件云的电话。这样做有助于确保机器使用最新的恶意软件的信息可以从微软恶意软件防护中心(MMPC)的研究团队,后端大数据,机器学习与逻辑。
*聚集保护遥测
利用最新的生态系统广泛的检测技术,通过云提供。微软团聚体保护遥测从超过十亿的客户,他们与众多的信号和交叉引用。
MMPC威胁情报利用算法构建和生态系统管理的威胁。当遇到可疑活动的终端产品,可以咨询云进行实时分析它在行动之前。
大数据和云的可用计算资源允许多态性和新出现的威胁和保护先进技术应用的快速检测。
在很高的水平,这是保护像地图:
“图1:云如何保护和遥测工程从终点又回来了。”
客户机选择发送遥测技术(检测),或定期(健康检查)对微软的恶意软件防护中心(MMPC)云服务,包括:
*遥测–威胁识别威胁,威胁相关的资源,和修复的结果
*可疑行为–收集样本,确定如何监控和调整
*心跳–检查系统的脉冲知道如果杀毒应用程序仍在运行,如果有更新的版本
MMPC云服务响应客户端的遥测:
*云行动–包括背景和一组从云指示如何处理潜在的威胁(例如,块)。
*云缓解响应–假阳性抑制误报恶意软件检测
收集到的数据是保密。看到微软系统中心2012端点保护隐私权声明
详情。为了帮助保护您的隐私,报告是通过加密连接发送到微软。相关数据分析。
我们的数据显示
“图2:保护地图比例可以超过半年”
如果我们把系统中心的端点保护数据为例,你会看到地图是贡献了10%的企业用户对系统的保护作用。
想像生活中没有它会有更多的机器–10%感染,10%更可能的入侵者。
前提
两基本会员先进会员启用云保护。看到微软主动保护服务(图)
微软系统中心的2012个端点保护隐私声明部分细节。
默认情况下,地图基本是所有微软最新的反恶意软件产品功能。为企业客户,你必须使它获得新的威胁是未来在云保护。
随着高级会员,你可以得到更多的信息关于恶意软件和/或可疑的行为。这样的信息可以给你的企业基础设施更好的保护。
让你的系统准备地图,看到在配置管理器端点保护介绍

所以,你可以做什么来保护您的企业?
保持你的系统启用图。
加入微软主动保护服务社区

看看地图,在你的微软安全产品启用,然后选择selectsettings地图:
“图3:”地图选项启用,微软反恶意软件的安全产品可以充分利用微软的云保护服务
“”
橡果公爵
发表于 2015-1-29 14:13:49 | 显示全部楼层
MSE就像浪客剑心,简单没有存在感,虽是最强主角,但使用逆刃刀,能不杀就不杀。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 07:18 , Processed in 0.126546 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表