Home > Enterprise Desktop Tips > > PatchGuard defends against rootkits in Windows Vista
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


PatchGuard defends against rootkits in Windows Vista


Brien M. Posey, MCSE
02.26.2008
Rating: --- (out of 5)


Advice for securing Windows
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Microsoft has long claimed that the best reason for upgrading to Windows Vista is to take advantage of all of the new security features. One of these new features is PatchGuard, a mechanism for preserving the integrity of various operating system (OS) components. Unfortunately, PatchGuard's protection is not as comprehensive as it might at first seem. In this article, I will explain why this is the case.

Before you can truly appreciate PatchGuard and what it does, here's a bit of historical background. Normally, when application developers code a Windows-based application, they use an application programming interface (API). An API provides a standardized, structured way for the application to interact with the Windows OS.

The problem with using an API is that it forces the application to play by OS rules. It also somewhat limits what the developer can do and for years some software developers have chosen to work around the various APIs.

While there isn't really anything wrong with working around an API, some software publishers take it one step further and use a coding technique called kernel hooking. Kernel hooking refers to the practice of replacing one of the kernel-level OS files with a modified version created by the software developer. Typically, this technique allows the application to use the kernel hook to bypass various OS safeguards and gain a deeper level of access to the OS or to the underlying hardware. This practice is especially common among software companies that develop antivirus products and other types of security products.

Microsoft has denounced the practice of kernel hooking. Depending on how the kernel hook is written, it can cause Windows to experience various stability and performance problems. Other applications may also cease to function correctly. After all, imagine what would happen if two different applications both attempted to replace the same kernel file with modified versions. I suspect that


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Microsoft Windows security tools
Using System Center Essentials as a patch management tool
Troubleshooting Microsoft WSUS connectivity issues
Windows security tools for the busy desktop administrator
Four Internet Explorer 8 group policy security settings
Microsoft Stirling security console delayed for more integration
Why should Windows shops use Microsoft Baseline Security Analyzer?
Using Sysinternals tools in security management scenarios
Sysinternals tools: A must-have for every Windows security toolbox
Windows security tools roundup
Top Windows client security tools for end users

Windows desktop security tips
Managing multiple passwords in Windows
Using System Center Essentials as a patch management tool
How Windows 7 stands up to security tests
Securing sensitive data on Windows-based laptops
Gathering and documenting your Windows desktop security policies
Windows desktop security standards documentation best practices
Desktop security preparation for a new wave of Windows apps
Four Internet Explorer 8 group policy security settings
The state of enterprise security and emerging threats in 2009
Why should Windows shops use Microsoft Baseline Security Analyzer?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


the main reason why Microsoft denounces the practice has to do with its inability to support something that has been modified.

Although kernel hooking was originally used with legitimate security programs, it wasn't long before malware authors jumped on the bandwagon. Kernel hooking is the process that makes creating rootkits possible. Most IT professionals no doubt remember the events of 2005 when the music industry was busted embedding rootkits in music CDs. Those rootkits used kernel hooking to modify the Windows kernel files in a way that would prevent music CDs from being copied. They designed rootkits in such a way as to mask any files or registry keys starting with $sys$, thus making it easy for malware authors to create malicious code that would be hidden by the existing rootkit.

Initially, it seems that PatchGuard would be the perfect solution to preventing kernel hooking, something that Microsoft realized several years ago. PatchGuard was actually introduced in Windows Server 2003 and Windows XP under the name Kernel Patch Protection.

So with Kernel Patch Protection now in the picture, why is it still possible to hook kernel files? One reason is that Kernel Patch Protection only exists on 64-bit versions of Windows. So many 32-bit programs exist that take advantage of kernel hooking that Microsoft did not want to risk having a major compatibility problem on its hands by implementing Kernel Patch Protection in 32-bit versions of Windows. At the time, so few application vendors were publishing 64-bit code that Microsoft decided it could safely implement Kernel Patch Protection into 64-bit versions of Windows without causing major problems for the entire software industry. Even today, PatchGuard still only runs on 64-bit systems.

Another reason why Kernel Patch Protection has been relatively ineffective so far is because it does not protect the entire OS. Kernel Patch Protection only provides the following types of protection:

The same restrictions are still in effect today with Windows Vista's PatchGuard. Supposedly, PatchGuard will eventually provide other types of protection.

It's going to be interesting to see what happens with PatchGuard. Some software companies have already created versions of their software that can circumvent PatchGuard, and several hacker websites have published tools for or articles on the subject of circumventing PatchGuard. Microsoft has created patches to block the various circumvention techniques.

If history is any indication, I think kernel hooking will always be something of a cat and mouse game. Hackers will continue to find new kernel hooking techniques, which will eventually be blocked by operating system patches.

Personally, I believe that PatchGuard and Kernel Patch Protection are good things. While it is obvious that these features are not capable of completely preventing rootkits, my hope is that they will send a message to legitimate software developers that they need to code their applications in ways that do not require modifications to the Windows kernel. When legitimate applications stop behaving like rootkits, it will become much easier to detect any rootkits that do make it onto the system.

About the author: Brien M. Posey, MCSE, has received Microsoft's Most Valuable Professional Award four times for his work with Windows Server, IIS and Exchange Server. He has served as CIO for a nationwide chain of hospitals and healthcare facilities, and was once a network administrator for Fort Knox.


Rate this Tip
To rate tips, you must be a member of SearchEnterpriseDesktop.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts