本帖最后由 wwwab 于 2025-11-28 21:26 编辑
杀毒?反作弊?微软:小了,格局小了,别说软件驱动了,外部硬件设备驱动我都要砍——未来数年,网络、摄像头、USB、打印机、电池、存储及音频等驱动类别的内核模式代码量将显著减少。“
现在来看,微软的野心是重塑一整个Windows内核生态啊,什么杀毒和反作弊,没针对你们,整个生态圈一视同仁
你猜为什么上文中突然提到一段——”另一方面对于那些出于性能或架构原因(如显卡驱动)必须保留在内核态的驱动程序,微软并未放松要求,而是实施了更严格的审核与控制措施。为了提升驱动的健壮性,微软引入了强制性的编译器安全防护、驱动隔离以及 DMA 重映射等技术手段,旨在将驱动故障的影响范围限制在最小,防止单一驱动错误导致系统级崩溃。“
《Preparing for what’s next: Windows security and resiliency innovations help organizations mitigate risks, recover faster and prepare for the era of AI》(为未来做准备:Windows安全与韧性创新帮助组织降低风险,加快恢复速度,并为AI时代做好准备)
原文:
Windows Resiliency Initiative brings recovery at scale
One year ago, at Ignite 2024, we introduced the Windows Resiliency Initiative (WRI), a focused set of improvements to help IT departments prevent incidents, manage those that occur and recover quickly.
Most incidents stem from change, and today’s rapid developments in security and AI are accelerating change across products, processes and how people work, raising the bar for IT.
Guided by your engagement and feedback, we’re proud to announce new Windows capabilities that help strengthen resilience across your environment.
Preventing incidents through driver resiliency
We invest continuously in Windows quality through deep validation of all new Windows capabilities and monthly security and quality updates. We also work continuously with our partners in the open and innovative Windows app and driver ecosystem to help ensure great reliability end-to-end.
We’ve recently made significant progress on two investments to help improve reliability in anti-virus drivers. Effective April 1, 2025, Version 3.0 of the Microsoft Virus Initiative added new requirements for all Windows antivirus (AV) partners to maintain signing rights for Windows AV drivers. In June, we released the first private preview of the Windows endpoint security platform, which shifts AV enforcement from the kernel to user mode. Running AV in user mode prevents bugs from taking down Windows, instead impacting only the AV app, while preserving AV functionality and AV partners’ ability to innovate.
We’re now extending the driver resiliency playbook across the Windows ecosystem beyond the AV scenario. In short, we’re raising the bar for driver signing and making it easier to build reliable drivers for Windows.
What’s changing:
Driver signing will require a higher security and resiliency bar with many new certification tests.
We are expanding Microsoft-provided Windows in-box drivers and APIs so partners can replace many custom kernel drivers with standardized Windows drivers or move logic to user mode.
Over the coming years, we expect a significant reduction in code that runs in kernel mode across driver classes such as networking, cameras, USB, printers, batteries, storage and audio.
We will continue to support third-party kernel mode drivers. We will not limit partners from innovating where we don’t have Windows in-box drivers, or from using kernel mode drivers where required to help ensure a great Windows experience and for scenarios without in-box coverage. Graphics drivers, for example, will continue to run in kernel mode for performance reasons.
For kernel-mode drivers, we’re adding practical guardrails that improve quality and contain faults before they become outages. These include new mandatory compiler safeguards to constrain driver behavior, driver isolation to limit blast radius, and DMA-remapping to prevent accidental driver access to kernel memory.
翻译:
Windows 韧性计划:实现规模化故障恢复
一年前,在2024年Ignite大会上,我们推出了Windows韧性计划(WRI),这是一系列针对性改进措施,旨在帮助IT部门预防事故、处理突发事件并快速恢复。
大多数事故源于变革。当前安全与AI领域的快速发展正在加速产品、流程及工作方式的变革,这对IT部门提出了更高要求。基于您的参与和反馈,我们自豪地宣布推出全新Windows功能,助力提升全环境韧性。
通过驱动韧性预防事故
我们通过深度验证所有新Windows功能及每月安全质量更新,持续投入Windows质量建设。同时与开放创新的Windows应用及驱动生态系统伙伴紧密合作,确保端到端的卓越可靠性。
近期我们在两项提升防病毒驱动可靠性的投资上取得重大进展:自2025年4月1日起,微软病毒防护计划3.0版新增要求,所有Windows防病毒合作伙伴须维持其驱动签名权限;6月我们发布了Windows终端安全平台首个私有预览版,将AV防护从内核模式迁移至用户模式。用户模式运行可避免系统崩溃,仅影响AV应用本身,同时保留防护功能与合作伙伴的创新空间。
现在,我们将这套驱动韧性方案扩展至AV场景之外的整个Windows生态系统。简言之,我们正在提高驱动签名标准,同时降低开发可靠驱动的难度。
主要变革:
• 驱动签名将执行更高安全韧性标准,新增多项认证测试
• 扩展微软内置驱动与API,支持合作伙伴用标准化驱动替代定制内核驱动或将逻辑移至用户模式
• 未来数年,网络、摄像头、USB、打印机、电池、存储及音频等驱动类别的内核模式代码量将显著减少
我们仍将支持第三方内核模式驱动,不会限制合作伙伴在无内置驱动领域创新,或在必要场景使用内核驱动以确保优质体验。例如显卡驱动仍将保留内核模式以保障性能。
针对内核模式驱动,我们新增实用防护措施:强制编译器安全机制约束驱动行为、驱动隔离限制故障范围、DMA重映射防止误访内核内存,从而在故障演变为宕机前提升质量并控制影响。 |