查看: 6539|回复: 12
收起左侧

[一般话题] Windows 10 will soon run Edge in a virtual machine to keep you safe

[复制链接]
EnZhSTReLniKoVa
发表于 2016-11-4 12:29:35 | 显示全部楼层 |阅读模式



   ATLANTA—Microsoft has announced that the next major update to Windows 10 will run its Edge browser in a lightweight virtual machine. Running the update in a virtual machine will make exploiting the browser and attacking the operating system or compromising user data more challenging.

   Called Windows Defender Application Guard for Microsoft Edge, the new capability builds on the virtual machine-based security that was first introduced last summer in Windows 10. Windows 10's Virtualization Based Security (VBS) uses small virtual machines and the Hyper-V hypervisor to isolate certain critical data and processes from the rest of the system. The most important of these is Credential Guard, which stores network credentials and password hashes in an isolated virtual machine. This isolation prevents the popular MimiKatz tool from harvesting those password hashes. In turn, it also prevents a hacker from breaking into one machine and then using stolen credentials to spread to other machines on the same network.

    The Edge browser already creates a secure sandbox for its processes, a technique that tries to limit the damage that can be done when malicious code runs within the browser. The sandbox has limited access to the rest of the system and its data, so successful exploits need to break free from the sandbox's constraints. Often they do this by attacking the operating system itself, using operating system flaws to elevate their privileges.

   Credential Guard's virtual machine is very small and lightweight, running only a relatively simple process to manage credentials. Application Guard will go much further by running large parts of the Edge browser within a virtual machine. This virtual machine won't, however, need a full operating system running inside it—just a minimal set of Windows features required to run the browser. Because Application Guard is running in a virtual machine it will have a much higher barrier between it and the host platform. It can't see other processes, it can't access local storage, it can't access any other installed applications, and, critically, it can't attack the kernel of the host system.

   In its first iteration, Application Guard will only be available for Edge. Microsoft won't provide an API or let other applications use it. As with other VBS features, Application Guard will also only be available to users of Windows 10 Enterprise, with administrative control through group policies. Administrators will be able to mark some sites as trusted, and those sites won't use the virtual machine. Admins also be able to control whether untrusted sites can use the clipboard or print.
Microsoft recognizes that this feature would be desirable on consumer machines, too, and not just for Edge. Other browsers such as Chrome would also benefit from this kind of protection. So too would Office's "Protected Mode" that's used for opening documents from untrusted sources.

   However, doing this has certain complexities. Currently, virtualized sites can't store persistent cookies, for example, because virtual machines get destroyed when the browser is closed. This may be acceptable for a locked-down enterprise environment, but it isn't a good fit for consumers.

   There are also compatibility constraints. VBS installs the Hyper-V hypervisor. This requires a processor with hardware virtualization support, and it also requires I/O virtualization (such as Intel's VT-d) to protect against certain known attacks. This means that some systems in the wild won't support it. There are also software concerns; only one hypervisor can be installed at a time, which means that a machine that's running Hyper-V cannot also run VMware Workstation or Virtual Box, say, or software that uses virtualization behind the scenes, such as the Bluestacks Android-on-Windows software.

   This virtualization also likely comes at some performance cost, although Microsoft is not saying just what that performance cost is right now.

   Nonetheless, this use of virtualization to harden a system is an exciting move. Experimental and special-use systems such as Qubes OS have used virtualization in a similar way, but are far from mainstream offerings. Microsoft is uniquely positioned take this kind of capability mainstream.

   Application Guard will become available later this year in Insider builds of Windows, hitting a stable version some time in 2017.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +1 收起 理由
驭龙 + 1 版区有你更精彩: )

查看全部评分

EnZhSTReLniKoVa
 楼主| 发表于 2016-11-4 12:34:05 | 显示全部楼层
   ATLANTA-Microsoft已经宣布,对Windows 10的下一个主要更新将在轻量级虚拟机中运行其Edge浏览器。 在虚拟机中运行更新会使利用浏览器和攻击操作系统或损害用户数据更具挑战性。
   Windows 10的基于虚拟化的安全(VBS)使用小型虚拟机和Hyper-V虚拟机管理程序来隔离 某些关键数据和过程从系统的其余部分。 其中最重要的是Credential Guard,它在隔离的虚拟机中存储网络凭据和密码散列。 这种隔离防止流行的MimiKatz工具收获这些密码哈希。 反过来,它也防止黑客入侵一台机器,然后使用被盗的凭证传播到同一网络上的其他机器。
  Edge浏览器已经为其进程创建了一个安全的沙盒,这是一种尝试限制恶意代码在浏览器中运行时可能造成的损害的技术。 沙箱对系统的其余部分及其数据的访问有限,因此成功的攻击需要从沙箱的限制中解脱出来。 通常他们通过攻击操作系统本身,使用操作系统缺陷来提升他们的权限。
  
  Credential Guard的虚拟机非常小巧轻便,只需运行相对简单的进程即可管理凭据。通过在虚拟机中运行大部分Edge浏览器,Application Guard将进一步发展。然而,这个虚拟机不需要在其中运行的完整操作系统 - 只是运行浏览器所需的最小的Windows功能集。由于Application Guard在虚拟机中运行,因此它与主机平台之间的隔离将更高。它无法查看其他进程,无法访问本地存储,也无法访问任何其他已安装的应用程序,而且严重地说,它无法攻击主机系统的内核。

   在其第一次迭代中,Application Guard将仅适用于Edge。 Microsoft不会提供API或让其他应用程序使用它。与其他VBS功能一样,Application Guard也仅对Windows 10 Enterprise的用户可用,通过组策略进行管理控制。管理员可以将某些网站标记为受信任的网站,这些网站不会使用虚拟机。管理员还能够控制不受信任的网站是否可以使用剪贴板或打印。
   Microsoft意识到此功能在用户计算机上也是可取的,而不仅仅是Edge。其他浏览器(如Chrome)也将受益于此类保护。 Office的“保护模式”也用于从不受信任的来源打开文档。
  然而,这样做有一定的复杂性。目前,虚拟化站点无法存储永久性Cookie,例如,因为虚拟机在浏览器关闭时被销毁。这对于锁定的企业环境可能是可以接受的,但它不适合消费者。

   还有兼容性限制。 VBS安装Hyper-V管理程序。这需要具有硬件虚拟化支持的处理器,并且还需要I / O虚拟化(例如Intel的VT-d)来防止某些已知的攻击。这意味着一些系统在野外将不支持它。还有软件问题;一次只能安装一个虚拟机管理程序,这意味着运行Hyper-V的机器无法运行VMware Workstation或Virtual Box,或者使用后台虚拟化的软件,例如Bluestacks Android-on-Windows软件。

这种虚拟化也可能带来一些性能成本,虽然微软不是说现在的性能成本是什么。

   尽管如此,这种使用虚拟化来硬化系统是一个令人兴奋的举动。实验和特殊用途系统如Qubes OS已经以类似的方式使用虚拟化,但是远离主流产品。微软是独一无二的定位采取这种能力主流。

Application Guard将在今年晚些时候在Windows的Insider版本中可用,在2017年有一段时间达到稳定版本。

评分

参与人数 1人气 +1 收起 理由
ELOHIM + 1 版区有你更精彩: )

查看全部评分

驭龙
发表于 2016-11-4 12:37:17 | 显示全部楼层
重头戏,终于要开始了,哈哈
EnZhSTReLniKoVa
 楼主| 发表于 2016-11-4 12:39:25 | 显示全部楼层
驭龙 发表于 2016-11-4 12:37
重头戏,终于要开始了,哈哈

的确是重头戏  哈哈 刚才无聊看外网 看到的  所以转发过来。
驭龙
发表于 2016-11-4 12:42:43 | 显示全部楼层
君陌潇 发表于 2016-11-4 12:39
的确是重头戏  哈哈 刚才无聊看外网 看到的  所以转发过来。

这个好像不是最新消息吧,目前的14959还没有WDAG和新WD

但是明年的更新确实是值得期待,另外WDATP也开始调整客户端模块了
EnZhSTReLniKoVa
 楼主| 发表于 2016-11-4 12:51:20 | 显示全部楼层
本帖最后由 君陌潇 于 2016-11-4 12:52 编辑
驭龙 发表于 2016-11-4 12:42
这个好像不是最新消息吧,目前的14959还没有WDAG和新WD

但是明年的更新确实是值得期待,另外WDATP也开 ...


9月28日的信息


14959大多数是手机端信息





http://www.winbeta.org/tags/windows-10

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
EnZhSTReLniKoVa
 楼主| 发表于 2016-11-4 12:53:34 | 显示全部楼层
驭龙 发表于 2016-11-4 12:42
这个好像不是最新消息吧,目前的14959还没有WDAG和新WD

但是明年的更新确实是值得期待,另外WDATP也开 ...

之前那个新界面 是 WD的 UWP版。。
驭龙
发表于 2016-11-4 12:55:55 | 显示全部楼层

这些媒体的新闻靠不住啊,都没有我之前发的WDAG信息完整,官方说WDAG是独立的虚拟化,并不是完全依赖于之前的Device Guard。

当然进一步的信息,只能等一段时间了
驭龙
发表于 2016-11-4 12:57:31 | 显示全部楼层
君陌潇 发表于 2016-11-4 12:53
之前那个新界面 是 WD的 UWP版。。

是的,我说的就是没有UWP的新WD
EnZhSTReLniKoVa
 楼主| 发表于 2016-11-4 12:59:23 | 显示全部楼层
驭龙 发表于 2016-11-4 12:55
这些媒体的新闻靠不住啊,都没有我之前发的WDAG信息完整,官方说WDAG是独立的虚拟化,并不是完全依赖于之 ...


可能 build 14959 是个开端。。毕竟要出统一的更新平台UUP
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 02:15 , Processed in 0.127163 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表