SlideShare una empresa de Scribd logo
1 de 44
Amit Gatenyo
Infrastructure & Security Manager
Dario IT Solutions ltd
054-2492499
amit.g@dario.co.il
Security
Security
SecurityWeb Virtualization
Reduces costs, increases
hardware utilization,
optimizes your
infrastructure, and
improves server
availability
Delivers rich web-based
experiences efficiently
and effectively
Provides unprecedented
levels of protection for
your network, your data,
and your business
Development Process
Secure Startup and shield
up at install
Code integrity
Windows service
hardening
Inbound and outbound
firewall
Restart Manager
Improved auditing
Network Access
Protection
Event Forwarding
Policy Based Networking
Server and Domain
Isolation
Removable Device
Installation Control
Active Directory Rights
Management Services
Security Compliance
Security
D DD
Defense In Depth
Reduce size of
high risk layers
Segment the
services
Increase #
of layers
Kernel DriversD
D User-mode Drivers
D
D D
Service
1
Service
2
Service
3
Service
…
Service
…
Service
A
Service
B
Windows® XP SP2/Server 2003 R2
LocalSystem
Windows Vista/Server 2008
Network Service
Local Service
LocalSystem
Firewall Restricted
Network Service
Network Restricted
Local Service
No Network Access
LocalSystem
Network Service
Fully Restricted
Local Service
Fully Restricted
‫נושא‬Windows XP / Windows Server
2003
Windows Vista / Windows
Server 2008
‫ההפעלה‬ ‫מערכת‬ ‫תהליכי‬ ‫הפעלת‬
‫מסביבת‬ ‫מופרדת‬ ‫בסביבה‬
‫המשתמש‬
‫אפשרית‬ ‫לא‬,‫אל‬ ‫לגשת‬ ‫ניתן‬
session 0‫המשתמש‬ ‫מסביבת‬
‫אפשרית‬,session 0‫מופרד‬
‫המשתמש‬ ‫מסביבת‬
‫אובייקטים‬ ‫על‬ ‫הרשאות‬ ‫מתן‬‫ה‬ ‫ברמת‬ ‫אפשרי‬–service account‫ה‬ ‫ברמת‬ ‫אפשרי‬–SID‫עבור‬
services
‫ההפעלה‬ ‫מערכת‬ ‫תהליכי‬ ‫הפעלת‬‫על‬ ‫בעיקר‬ ‫מתבססת‬LocalSystem‫מאפשר‬ ‫אשר‬ ‫מנגנון‬ ‫על‬ ‫מתבססת‬
‫מתוך‬ ‫חלקיות‬ ‫הרשאות‬ ‫ביזור‬
‫ה‬ ‫הרשאות‬–LocalSystem/
LocalService/NetworkService
‫ב‬ ‫שימוש‬–write restricted token‫קיים‬ ‫לא‬‫אפשרי‬
‫ה‬ ‫גישת‬ ‫הגבלת‬-services‫למשאבי‬
‫הרשת‬
‫חלקי‬ ‫באופן‬ ‫רק‬ ‫אפשרית‬(inbound)
,‫ה‬ ‫בהפעלת‬ ‫מותנית‬–windows
firewall
‫ה‬ ‫מרבית‬–windows services
‫למשאבי‬ ‫לגישה‬ ‫ביחס‬ ‫מוקשחים‬
‫תלות‬ ‫ללא‬ ‫אוטומטי‬ ‫באופן‬ ‫הרשת‬
‫ה‬ ‫בהפעלת‬–windows firewall,
‫עבור‬app services‫להגדיר‬ ‫ניתן‬
‫באמצעות‬ ‫הקשחה‬ ‫חוקי‬ ‫עבורם‬API
Combined firewall and IPsec managementFirewall rules become more intelligentPolicy-based networking
‫נושא‬Windows XP / Windows Server 2003Windows Vista / Windows Server 2008
‫נכנסת‬ ‫נתונים‬ ‫תעבורת‬ ‫לגבי‬ ‫מדיניות‬ ‫אכיפת‬
(inbound)
‫אפשרית‬‫אפשרית‬
‫יוצאת‬ ‫נתונים‬ ‫תעבורת‬ ‫לגבי‬ ‫מדיניות‬ ‫אכיפת‬
(outbound)
‫אפשרית‬ ‫לא‬‫אפשרית‬
‫העברת‬ ‫אבטחת‬ ‫תצורת‬ ‫לגבי‬ ‫מדיניות‬ ‫אכיפת‬
‫נתונים‬
‫ה‬ ‫ברמת‬ ‫נתמך‬ ‫לא‬–firewall,‫למימוש‬ ‫אפשרי‬
‫ע‬"‫ה‬ ‫י‬–IP security policies(GPO)
‫באמצעות‬ ‫אפשרית‬IPSEC
‫בדומיין‬ ‫לחברות‬ ‫בהתאם‬ ‫מדיניות‬ ‫אכיפת‬‫אפשרית‬ ‫לא‬‫אפשרית‬
‫משתמש‬ ‫לשם‬ ‫בהתאם‬ ‫מדיניות‬ ‫אכיפת‬/‫שם‬
‫מחשב‬
‫אפשרית‬ ‫לא‬‫אפשרית‬
‫המחשב‬ ‫אליה‬ ‫לרשת‬ ‫בהתאם‬ ‫מדיניות‬ ‫אכיפת‬
‫מחובר‬
‫אפשרית‬ ‫לא‬‫אפשרית‬–‫קיימים‬3‫פרופילים‬
(public/private/domain)
‫ב‬ ‫תמיכה‬–windows service hardening‫קיימת‬ ‫לא‬‫קיימת‬
‫באמצעות‬ ‫חוקים‬ ‫בהחלת‬ ‫תמיכה‬GPO‫מה‬ ‫שונה‬ ‫הממשק‬ ‫אבל‬ ‫אפשרית‬–windows
firewall MMC
‫ל‬ ‫לחלוטין‬ ‫זהה‬ ‫באופן‬ ‫אפשרית‬–windows
firewall advanced security MMC
‫עקיפה‬ ‫חוקי‬ ‫קביעת‬(bypass)‫תקשורת‬ ‫עבור‬
‫נכנסת‬/‫ספציפיים‬ ‫ממחשבים‬ ‫יוצאת‬
‫חלקי‬ ‫באופן‬ ‫אפשרית‬‫אפשרית‬
‫אובייקטים‬ ‫סמך‬ ‫על‬ ‫בהתאם‬ ‫חוקים‬ ‫קביעת‬
‫מה‬–Active Directory
‫אפשרית‬ ‫לא‬‫אפשרית‬
‫ב‬ ‫תמיכה‬–IPv6‫דורשת‬ ‫אבל‬ ‫אפשרית‬SP(‫עבור‬Windows XP
– SP2,‫עבור‬Windows Server 2003 – SP1)
‫ב‬ ‫צורך‬ ‫ללא‬ ‫אפשרית‬–SP
Only a subset of the executable files and DLLs installed
No GUI interface installed
9 available Server Roles
Can be managed with remote tools
Customization
Troubleshooting
Administration
True application deployment
Application and health
management
• Arsenal of Admin Tools
• Delegated Management
• Secure Remote Management
• Shared Config for Web Farms
Better Tools
Intuitive, Task Oriented GUI
.NET Management API
Unified WMI Provider for IIS/ASP.NET
Powerful Command Line Support
Rich Runtime State Information
Automatic Failure Tracing & Logging
Site Owner Web.config
XML
Administrator
Internet
Manage Remotely
Secure HTTPS
AppHost.config
XML
Shared
Config
Shared App Hosting
Web FarmApp
Group Policy allows central encryption policy and provides Branch
Office protection
Provides data protection, even when the system is in unauthorized hands
or is running a different or exploiting Operating System
Uses a v1.2 TPM or USB flash drive for key storage
Full Volume
Encryption Key
(FVEK)Encryption
Policy
‫פתרון‬
‫מתקפה‬
‫בזמן‬
hibern
ate
‫מתקפה‬
‫בזמן‬
sleep/
standby
‫מתקפה‬
‫כנגד‬
‫תהליך‬
‫האתחול‬
‫מתקפה‬
‫כנגד‬
online
‫מערכת‬
‫ההפעלה‬
‫חשיפת‬
‫מפתחות‬
‫בזמן‬
offline
‫מתקפה‬
‫המבוססת‬
‫על‬
‫חשיפת‬
‫סיסמאות‬
‫טעויות‬
‫משתמש‬
‫זליגת‬
‫מידע‬
plaint
ext
‫גניבת‬
‫המחשב‬
‫בלבד‬ TPM
‫בלבד‬ USB
PIN
‫בשילוב‬
TPM

USB
‫בשילוב‬
TPM

AD RMS protects access to an
organization’s digital files
AD RMS in Windows Server 2008
includes several new features
Improved installation and
administration experience
Self-enrollment of the AD RMS
cluster
Integration with AD Federation
Services
New AD RMS administrative roles
Information Author The Recipient
Protected emails
Add users
with Read
and Change
permissions Verify
aliases
& DLs via
AD
Add
advanced
permission
s
Set expiration
date
Enable
print, copy
permissions
Add/remove
additional users
Contact for
permission
requests
Enable
viewing via
RMA
Protected doc library
AD FS provides an identity
access solution
Deploy federation servers in
multiple organizations to
facilitate business-to-
business (B2B) transactions
AD FS provides a Web-
based, SSO solution
AD FS interoperates with
other security products that
support the Web Services
Architecture
AD FS improved in Windows
Server 2008
Web
Server
Account
Federation
Server
Resource
Federation
Server
LeadcomDario
Federation
Trust
Main Office Branch Office
Features
Benefits
RODC
Enterprise PKI (PKIView) Online Certificate Status
Protocol (OSCP)
Network Device Enrollment
Service
Web Enrollment
Cryptography Next Generation
(CNG)
Includes algorithms for encryption, digital signatures, key exchange, and
hashing
Supports cryptography in kernel mode
Supports the current set of CryptoAPI 1.0 algorithms
Support for elliptic curve cryptography (ECC) algorithms
Perform basic cryptographic operations, such as creating hashes and
encrypting and decrypting data
‫נושא‬CryptoAPICNG
‫סימטרית‬ ‫בהצפנה‬ ‫תמיכה‬
‫א‬ ‫בהצפנה‬ ‫תמיכה‬-‫סימטרית‬
‫ב‬ ‫תמיכה‬–hash
‫דיגיטליות‬ ‫בתעודות‬ ‫תמיכה‬‫באמצעות‬CAPI 2.0
‫ארכיטקטורה‬CSPProtocol provider, CNG routers, CNG primitives
‫הצפנה‬ ‫במנגוני‬ ‫תמיכה‬legacy
‫אין‬
‫אקראיים‬ ‫מספרים‬ ‫מחולל‬ ‫החלפת‬
‫מחדש‬ ‫הקוד‬ ‫כתיבת‬ ‫דורשת‬‫בקוד‬ ‫מהותי‬ ‫שינוי‬ ‫ללא‬ ‫אפשרית‬
‫חדשים‬ ‫אלגוריתמים‬ ‫שילוב‬
‫אפשרי‬ ‫לא‬–‫קשיחה‬ ‫רשימה‬‫אפשרית‬–‫לעידכון‬ ‫וניתנת‬ ‫דינמית‬ ‫רשימה‬
‫מרכזי‬ ‫ניהול‬ ‫מנגנון‬
‫אין‬‫ה‬ ‫באמצעות‬ ‫אפשרי‬–key storage API
‫ב‬ ‫תמיכה‬–Suite B‫אין‬
‫אלגוריתמים‬
CAPI 1.0
AES , SHA1 , SHA2, DSA,
RSA,ECC,DH,ECDSA,ECDH,MD2,MD4,MD5, CAPI
1.0
‫הפרטי‬ ‫המפתח‬ ‫הפרדת‬
‫מהאפליקציה‬
‫אפשרי‬ ‫לא‬‫באמצעות‬ ‫לביצוע‬ ‫אפשרי‬key isolation process
‫המפתחות‬ ‫שמירת‬ ‫מיקום‬
‫הפרטיים‬
‫ל‬ ‫מקושר‬–SID,‫תהליך‬ ‫על‬ ‫מקשה‬
‫דומיינים‬ ‫בין‬ ‫מעבר‬
‫ל‬ ‫מקושר‬ ‫לא‬–SID,‫בין‬ ‫מעבר‬ ‫תהליך‬ ‫לבצע‬ ‫קל‬
‫דומיינים‬
‫המפתחות‬ ‫שמירת‬ ‫פורמט‬‫סיומת‬REG,‫של‬ ‫מגבלה‬256‫תווים‬
‫בשם‬
‫סיומת‬ ‫ללא‬ ‫חדש‬ ‫פורמט‬REG,‫של‬ ‫מגבלה‬512‫תווים‬
‫בשם‬
Internet
Perimeter
Network
Corporate
Network
Remote/
Mobile User
Terminal
Services
Gateway
Network
Policy Server
Active
Directory DC
Tunnels RDP
over HTTPs
Strips off RDP
/ HTTPs
Terminal
Servers
and other
RDP Hosts
RDP traffic
passed to TS
Internet
Remediation
Servers
Example: Patch
Restricted
Network
Windows
Client
Policy
compliant
NPS
DHCP, VPN
Switch/Router
Policy Servers
such as: Patch, AV
Corporate Network
Not policy
compliant
What is Network Access
Protection?
Health Policy Validation Health Policy Compliance
Ability to Provide Limited
Access
Enhanced Security
Increased Business Value
1
Remediation
Servers
Example: Patch
Restricted
Network
1
Windows
Client
2
2
DHCP, VPN or Switch/Router relays health status
to Microsoft Network Policy Server (RADIUS)
3
3
Network Policy Server (NPS) validates against IT-
defined health policy
4
If not policy compliant, client is put in a
restricted VLAN and given access to fix up
resources to download patches, configurations,
signatures (Repeat 1 - 4)
Not policy
compliant
5
If policy compliant, client is granted full access
to corporate network
Policy
compliant
NPS
DHCP, VPN
Switch/Router
4
Policy Servers
such as: Patch, AV
Corporate Network
5
Client requests access to network and presents
current health state
41
Internet Protocol security (IPsec)-protected
communications
IEEE 802.1X-authenticated network
connections
Remote access virtual private network (VPN)
connections
Dynamic Host Configuration Protocol (DHCP)
configuration
Policy based – was network access
allowed
• Health based - % compliant per SHA
http://www.dario.co.il/blog
Amit Gatenyo
Infrastructure & Security Manager
Dario IT Solutions ltd
amit.g@dario.co.il
054-2492499

Más contenido relacionado

Destacado

Rock N Roll Collection Elvs Prsly 01
Rock  N   Roll  Collection  Elvs Prsly 01Rock  N   Roll  Collection  Elvs Prsly 01
Rock N Roll Collection Elvs Prsly 01ForMovieFansOnly
 
20120301 讓遺囑不只是遺囑
20120301 讓遺囑不只是遺囑20120301 讓遺囑不只是遺囑
20120301 讓遺囑不只是遺囑LIN JACK
 
Jpt 13
Jpt 13Jpt 13
Jpt 13ojarsk
 
Laurent Sciboz - Professeur HES-SO Valais-Wallis - TechnoArk 2014
Laurent Sciboz - Professeur HES-SO Valais-Wallis - TechnoArk 2014Laurent Sciboz - Professeur HES-SO Valais-Wallis - TechnoArk 2014
Laurent Sciboz - Professeur HES-SO Valais-Wallis - TechnoArk 2014TechnoArk
 
The Future Of Marketing And Advertising Aug 2009
The Future Of Marketing And Advertising Aug 2009The Future Of Marketing And Advertising Aug 2009
The Future Of Marketing And Advertising Aug 2009jeannieodza
 
雲南-從阿詩瑪的家鄉到玉龍雪山
雲南-從阿詩瑪的家鄉到玉龍雪山雲南-從阿詩瑪的家鄉到玉龍雪山
雲南-從阿詩瑪的家鄉到玉龍雪山Amy Yeh
 
Earthhour2011 110328163802 Phpapp01
Earthhour2011 110328163802 Phpapp01Earthhour2011 110328163802 Phpapp01
Earthhour2011 110328163802 Phpapp01Simona Converso
 
TU Delft OpenCoursWare: were will we be in 3 years
TU Delft OpenCoursWare: were will we be in 3 yearsTU Delft OpenCoursWare: were will we be in 3 years
TU Delft OpenCoursWare: were will we be in 3 yearsWillem van Valkenburg
 
14a 2 t4_chapterfourteenpowerpoint_new
14a 2 t4_chapterfourteenpowerpoint_new14a 2 t4_chapterfourteenpowerpoint_new
14a 2 t4_chapterfourteenpowerpoint_newsagebennet
 
大南崁地區希望工程簡報檔
大南崁地區希望工程簡報檔 大南崁地區希望工程簡報檔
大南崁地區希望工程簡報檔 bhyjtw2
 
天下雜誌 - 宮崎駿:希望 快樂 溫暖
天下雜誌 - 宮崎駿:希望  快樂  溫暖天下雜誌 - 宮崎駿:希望  快樂  溫暖
天下雜誌 - 宮崎駿:希望 快樂 溫暖Rose Hwang
 

Destacado (20)

Ibm irl
Ibm irlIbm irl
Ibm irl
 
Coco
CocoCoco
Coco
 
Magic Cards
Magic CardsMagic Cards
Magic Cards
 
Rock N Roll Collection Elvs Prsly 01
Rock  N   Roll  Collection  Elvs Prsly 01Rock  N   Roll  Collection  Elvs Prsly 01
Rock N Roll Collection Elvs Prsly 01
 
Gonorrhea
GonorrheaGonorrhea
Gonorrhea
 
20120301 讓遺囑不只是遺囑
20120301 讓遺囑不只是遺囑20120301 讓遺囑不只是遺囑
20120301 讓遺囑不只是遺囑
 
Jpt 13
Jpt 13Jpt 13
Jpt 13
 
Foto s mooi
Foto s mooiFoto s mooi
Foto s mooi
 
Laurent Sciboz - Professeur HES-SO Valais-Wallis - TechnoArk 2014
Laurent Sciboz - Professeur HES-SO Valais-Wallis - TechnoArk 2014Laurent Sciboz - Professeur HES-SO Valais-Wallis - TechnoArk 2014
Laurent Sciboz - Professeur HES-SO Valais-Wallis - TechnoArk 2014
 
The Future Of Marketing And Advertising Aug 2009
The Future Of Marketing And Advertising Aug 2009The Future Of Marketing And Advertising Aug 2009
The Future Of Marketing And Advertising Aug 2009
 
New thought
New thoughtNew thought
New thought
 
優質NPO的評選標準
優質NPO的評選標準優質NPO的評選標準
優質NPO的評選標準
 
雲南-從阿詩瑪的家鄉到玉龍雪山
雲南-從阿詩瑪的家鄉到玉龍雪山雲南-從阿詩瑪的家鄉到玉龍雪山
雲南-從阿詩瑪的家鄉到玉龍雪山
 
Earthhour2011 110328163802 Phpapp01
Earthhour2011 110328163802 Phpapp01Earthhour2011 110328163802 Phpapp01
Earthhour2011 110328163802 Phpapp01
 
TU Delft OpenCoursWare: were will we be in 3 years
TU Delft OpenCoursWare: were will we be in 3 yearsTU Delft OpenCoursWare: were will we be in 3 years
TU Delft OpenCoursWare: were will we be in 3 years
 
14a 2 t4_chapterfourteenpowerpoint_new
14a 2 t4_chapterfourteenpowerpoint_new14a 2 t4_chapterfourteenpowerpoint_new
14a 2 t4_chapterfourteenpowerpoint_new
 
大南崁地區希望工程簡報檔
大南崁地區希望工程簡報檔 大南崁地區希望工程簡報檔
大南崁地區希望工程簡報檔
 
天下雜誌 - 宮崎駿:希望 快樂 溫暖
天下雜誌 - 宮崎駿:希望  快樂  溫暖天下雜誌 - 宮崎駿:希望  快樂  溫暖
天下雜誌 - 宮崎駿:希望 快樂 溫暖
 
Entre Tu Y Dios
Entre Tu Y DiosEntre Tu Y Dios
Entre Tu Y Dios
 
Power point gbi
Power point gbiPower point gbi
Power point gbi
 

Similar a Windows 2008 Security

W7 for IT Professionals
W7 for IT ProfessionalsW7 for IT Professionals
W7 for IT Professionalsguest632c73
 
W7 Enterprise
W7 EnterpriseW7 Enterprise
W7 Enterprisearalves
 
Desktop management and support
Desktop management and supportDesktop management and support
Desktop management and supportStephen Rose
 
Sudheer Devu _4 Years _System Administrator
Sudheer Devu _4 Years _System AdministratorSudheer Devu _4 Years _System Administrator
Sudheer Devu _4 Years _System AdministratorSudheer Kumar
 
Wave 14 - Winodws 7 Security Story Core by MVP Azra Rizal
Wave 14 - Winodws 7 Security Story Core by MVP Azra RizalWave 14 - Winodws 7 Security Story Core by MVP Azra Rizal
Wave 14 - Winodws 7 Security Story Core by MVP Azra RizalQuek Lilian
 
Windows 7 Security Enhancements
Windows 7 Security EnhancementsWindows 7 Security Enhancements
Windows 7 Security EnhancementsPresentologics
 
Module 03 installing, upgrading, and migrating to windows 7
Module 03   installing, upgrading, and migrating to windows 7Module 03   installing, upgrading, and migrating to windows 7
Module 03 installing, upgrading, and migrating to windows 7aesthetics00
 
Ihab hanna resume
Ihab hanna  resume Ihab hanna  resume
Ihab hanna resume Ihab Gouher
 
Ihab hanna resume
Ihab hanna  resume Ihab hanna  resume
Ihab hanna resume Ihab Gouher
 
Ster-Kinekor - Artec Case Study 07-09-03
Ster-Kinekor - Artec Case Study 07-09-03Ster-Kinekor - Artec Case Study 07-09-03
Ster-Kinekor - Artec Case Study 07-09-03Francois Combrink
 
0505 Windows Server 2008 一日精華營 PartI
0505 Windows Server 2008 一日精華營 PartI0505 Windows Server 2008 一日精華營 PartI
0505 Windows Server 2008 一日精華營 PartITimothy Chen
 
Windows 7 And Windows Server 2008 R2 Combined Value
Windows 7 And Windows Server 2008 R2 Combined ValueWindows 7 And Windows Server 2008 R2 Combined Value
Windows 7 And Windows Server 2008 R2 Combined ValueAmit Gatenyo
 

Similar a Windows 2008 Security (20)

W7 for IT Professionals
W7 for IT ProfessionalsW7 for IT Professionals
W7 for IT Professionals
 
W7 Enterprise
W7 EnterpriseW7 Enterprise
W7 Enterprise
 
Desktop management and support
Desktop management and supportDesktop management and support
Desktop management and support
 
Sudheer Devu _4 Years _System Administrator
Sudheer Devu _4 Years _System AdministratorSudheer Devu _4 Years _System Administrator
Sudheer Devu _4 Years _System Administrator
 
KiranNew_Resume
KiranNew_ResumeKiranNew_Resume
KiranNew_Resume
 
jithin
jithinjithin
jithin
 
Wave 14 - Winodws 7 Security Story Core by MVP Azra Rizal
Wave 14 - Winodws 7 Security Story Core by MVP Azra RizalWave 14 - Winodws 7 Security Story Core by MVP Azra Rizal
Wave 14 - Winodws 7 Security Story Core by MVP Azra Rizal
 
Extranets Presenatation For Ala
Extranets Presenatation For AlaExtranets Presenatation For Ala
Extranets Presenatation For Ala
 
Windows 7 Security Enhancements
Windows 7 Security EnhancementsWindows 7 Security Enhancements
Windows 7 Security Enhancements
 
Module 03 installing, upgrading, and migrating to windows 7
Module 03   installing, upgrading, and migrating to windows 7Module 03   installing, upgrading, and migrating to windows 7
Module 03 installing, upgrading, and migrating to windows 7
 
Rajeev Parameswaran Resume
Rajeev Parameswaran ResumeRajeev Parameswaran Resume
Rajeev Parameswaran Resume
 
Venugopal -CV
Venugopal -CVVenugopal -CV
Venugopal -CV
 
Resume
ResumeResume
Resume
 
Resume updated
Resume updatedResume updated
Resume updated
 
01Liaqat ali cv
01Liaqat ali cv01Liaqat ali cv
01Liaqat ali cv
 
Ihab hanna resume
Ihab hanna  resume Ihab hanna  resume
Ihab hanna resume
 
Ihab hanna resume
Ihab hanna  resume Ihab hanna  resume
Ihab hanna resume
 
Ster-Kinekor - Artec Case Study 07-09-03
Ster-Kinekor - Artec Case Study 07-09-03Ster-Kinekor - Artec Case Study 07-09-03
Ster-Kinekor - Artec Case Study 07-09-03
 
0505 Windows Server 2008 一日精華營 PartI
0505 Windows Server 2008 一日精華營 PartI0505 Windows Server 2008 一日精華營 PartI
0505 Windows Server 2008 一日精華營 PartI
 
Windows 7 And Windows Server 2008 R2 Combined Value
Windows 7 And Windows Server 2008 R2 Combined ValueWindows 7 And Windows Server 2008 R2 Combined Value
Windows 7 And Windows Server 2008 R2 Combined Value
 

Más de Amit Gatenyo

System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows IntuneSystem Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows IntuneAmit Gatenyo
 
ענן פרטי וענן ציבורי: לא שני עולמות מתחרים אלא שני מימדים לאותו העולם
ענן פרטי וענן ציבורי: לא שני עולמות מתחרים אלא שני מימדים לאותו העולםענן פרטי וענן ציבורי: לא שני עולמות מתחרים אלא שני מימדים לאותו העולם
ענן פרטי וענן ציבורי: לא שני עולמות מתחרים אלא שני מימדים לאותו העולםAmit Gatenyo
 
Hybrid Cloud – Live Demo
Hybrid Cloud – Live DemoHybrid Cloud – Live Demo
Hybrid Cloud – Live DemoAmit Gatenyo
 
RemoteFX & RDS in Windows Server 2012
RemoteFX & RDS in Windows Server 2012RemoteFX & RDS in Windows Server 2012
RemoteFX & RDS in Windows Server 2012Amit Gatenyo
 
Asset Management & Service Manager 2012
Asset Management & Service Manager 2012Asset Management & Service Manager 2012
Asset Management & Service Manager 2012Amit Gatenyo
 
Windows 2012 Technical Overview
Windows 2012 Technical OverviewWindows 2012 Technical Overview
Windows 2012 Technical OverviewAmit Gatenyo
 
Hyper-V Best Practices & Tips and Tricks
Hyper-V Best Practices & Tips and TricksHyper-V Best Practices & Tips and Tricks
Hyper-V Best Practices & Tips and TricksAmit Gatenyo
 
Getting the most out of RDS (Terminal Services)
Getting the most out of RDS (Terminal Services)Getting the most out of RDS (Terminal Services)
Getting the most out of RDS (Terminal Services)Amit Gatenyo
 
System Center 2012 Overview
System Center 2012 OverviewSystem Center 2012 Overview
System Center 2012 OverviewAmit Gatenyo
 
Upgrading AD from Windows Server 2003 to Windows Server 2008 R2
Upgrading AD from Windows Server 2003 to Windows Server 2008 R2Upgrading AD from Windows Server 2003 to Windows Server 2008 R2
Upgrading AD from Windows Server 2003 to Windows Server 2008 R2Amit Gatenyo
 
SCOM 2012 & SCCM 2012
SCOM 2012 & SCCM 2012SCOM 2012 & SCCM 2012
SCOM 2012 & SCCM 2012Amit Gatenyo
 
System Center Configuration Manager 2012 Overview
System Center Configuration Manager 2012 OverviewSystem Center Configuration Manager 2012 Overview
System Center Configuration Manager 2012 OverviewAmit Gatenyo
 
System Center Data Protection Manager 2012 Overview
System Center Data Protection Manager 2012 OverviewSystem Center Data Protection Manager 2012 Overview
System Center Data Protection Manager 2012 OverviewAmit Gatenyo
 
RemoteFX - Rich End User Experience for VDI and Remote Desktops
RemoteFX - Rich End User Experience for VDI and Remote DesktopsRemoteFX - Rich End User Experience for VDI and Remote Desktops
RemoteFX - Rich End User Experience for VDI and Remote DesktopsAmit Gatenyo
 
System Center Datacenter Cloud Management Vision & Roadmap
System Center Datacenter Cloud Management Vision & RoadmapSystem Center Datacenter Cloud Management Vision & Roadmap
System Center Datacenter Cloud Management Vision & RoadmapAmit Gatenyo
 
System Center 2012 Technical Overview
System Center 2012 Technical OverviewSystem Center 2012 Technical Overview
System Center 2012 Technical OverviewAmit Gatenyo
 
System Center Service Manager 2012 Overview
System Center Service Manager 2012 OverviewSystem Center Service Manager 2012 Overview
System Center Service Manager 2012 OverviewAmit Gatenyo
 
System Center Orchestrator 2012 Overview
System Center Orchestrator 2012 OverviewSystem Center Orchestrator 2012 Overview
System Center Orchestrator 2012 OverviewAmit Gatenyo
 
System Center Virtual Machine Manager 2012 - Whats New
System Center  Virtual Machine Manager 2012 - Whats NewSystem Center  Virtual Machine Manager 2012 - Whats New
System Center Virtual Machine Manager 2012 - Whats NewAmit Gatenyo
 
Microsoft Private Cloud Strategy
Microsoft Private Cloud StrategyMicrosoft Private Cloud Strategy
Microsoft Private Cloud StrategyAmit Gatenyo
 

Más de Amit Gatenyo (20)

System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows IntuneSystem Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
 
ענן פרטי וענן ציבורי: לא שני עולמות מתחרים אלא שני מימדים לאותו העולם
ענן פרטי וענן ציבורי: לא שני עולמות מתחרים אלא שני מימדים לאותו העולםענן פרטי וענן ציבורי: לא שני עולמות מתחרים אלא שני מימדים לאותו העולם
ענן פרטי וענן ציבורי: לא שני עולמות מתחרים אלא שני מימדים לאותו העולם
 
Hybrid Cloud – Live Demo
Hybrid Cloud – Live DemoHybrid Cloud – Live Demo
Hybrid Cloud – Live Demo
 
RemoteFX & RDS in Windows Server 2012
RemoteFX & RDS in Windows Server 2012RemoteFX & RDS in Windows Server 2012
RemoteFX & RDS in Windows Server 2012
 
Asset Management & Service Manager 2012
Asset Management & Service Manager 2012Asset Management & Service Manager 2012
Asset Management & Service Manager 2012
 
Windows 2012 Technical Overview
Windows 2012 Technical OverviewWindows 2012 Technical Overview
Windows 2012 Technical Overview
 
Hyper-V Best Practices & Tips and Tricks
Hyper-V Best Practices & Tips and TricksHyper-V Best Practices & Tips and Tricks
Hyper-V Best Practices & Tips and Tricks
 
Getting the most out of RDS (Terminal Services)
Getting the most out of RDS (Terminal Services)Getting the most out of RDS (Terminal Services)
Getting the most out of RDS (Terminal Services)
 
System Center 2012 Overview
System Center 2012 OverviewSystem Center 2012 Overview
System Center 2012 Overview
 
Upgrading AD from Windows Server 2003 to Windows Server 2008 R2
Upgrading AD from Windows Server 2003 to Windows Server 2008 R2Upgrading AD from Windows Server 2003 to Windows Server 2008 R2
Upgrading AD from Windows Server 2003 to Windows Server 2008 R2
 
SCOM 2012 & SCCM 2012
SCOM 2012 & SCCM 2012SCOM 2012 & SCCM 2012
SCOM 2012 & SCCM 2012
 
System Center Configuration Manager 2012 Overview
System Center Configuration Manager 2012 OverviewSystem Center Configuration Manager 2012 Overview
System Center Configuration Manager 2012 Overview
 
System Center Data Protection Manager 2012 Overview
System Center Data Protection Manager 2012 OverviewSystem Center Data Protection Manager 2012 Overview
System Center Data Protection Manager 2012 Overview
 
RemoteFX - Rich End User Experience for VDI and Remote Desktops
RemoteFX - Rich End User Experience for VDI and Remote DesktopsRemoteFX - Rich End User Experience for VDI and Remote Desktops
RemoteFX - Rich End User Experience for VDI and Remote Desktops
 
System Center Datacenter Cloud Management Vision & Roadmap
System Center Datacenter Cloud Management Vision & RoadmapSystem Center Datacenter Cloud Management Vision & Roadmap
System Center Datacenter Cloud Management Vision & Roadmap
 
System Center 2012 Technical Overview
System Center 2012 Technical OverviewSystem Center 2012 Technical Overview
System Center 2012 Technical Overview
 
System Center Service Manager 2012 Overview
System Center Service Manager 2012 OverviewSystem Center Service Manager 2012 Overview
System Center Service Manager 2012 Overview
 
System Center Orchestrator 2012 Overview
System Center Orchestrator 2012 OverviewSystem Center Orchestrator 2012 Overview
System Center Orchestrator 2012 Overview
 
System Center Virtual Machine Manager 2012 - Whats New
System Center  Virtual Machine Manager 2012 - Whats NewSystem Center  Virtual Machine Manager 2012 - Whats New
System Center Virtual Machine Manager 2012 - Whats New
 
Microsoft Private Cloud Strategy
Microsoft Private Cloud StrategyMicrosoft Private Cloud Strategy
Microsoft Private Cloud Strategy
 

Último

Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embeddingZilliz
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesZilliz
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 

Último (20)

Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embedding
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector Databases
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 

Windows 2008 Security

  • 1. Amit Gatenyo Infrastructure & Security Manager Dario IT Solutions ltd 054-2492499 amit.g@dario.co.il Security
  • 2. Security SecurityWeb Virtualization Reduces costs, increases hardware utilization, optimizes your infrastructure, and improves server availability Delivers rich web-based experiences efficiently and effectively Provides unprecedented levels of protection for your network, your data, and your business
  • 3. Development Process Secure Startup and shield up at install Code integrity Windows service hardening Inbound and outbound firewall Restart Manager Improved auditing Network Access Protection Event Forwarding Policy Based Networking Server and Domain Isolation Removable Device Installation Control Active Directory Rights Management Services Security Compliance Security
  • 4. D DD Defense In Depth Reduce size of high risk layers Segment the services Increase # of layers Kernel DriversD D User-mode Drivers D D D Service 1 Service 2 Service 3 Service … Service … Service A Service B
  • 5. Windows® XP SP2/Server 2003 R2 LocalSystem Windows Vista/Server 2008 Network Service Local Service LocalSystem Firewall Restricted Network Service Network Restricted Local Service No Network Access LocalSystem Network Service Fully Restricted Local Service Fully Restricted
  • 6. ‫נושא‬Windows XP / Windows Server 2003 Windows Vista / Windows Server 2008 ‫ההפעלה‬ ‫מערכת‬ ‫תהליכי‬ ‫הפעלת‬ ‫מסביבת‬ ‫מופרדת‬ ‫בסביבה‬ ‫המשתמש‬ ‫אפשרית‬ ‫לא‬,‫אל‬ ‫לגשת‬ ‫ניתן‬ session 0‫המשתמש‬ ‫מסביבת‬ ‫אפשרית‬,session 0‫מופרד‬ ‫המשתמש‬ ‫מסביבת‬ ‫אובייקטים‬ ‫על‬ ‫הרשאות‬ ‫מתן‬‫ה‬ ‫ברמת‬ ‫אפשרי‬–service account‫ה‬ ‫ברמת‬ ‫אפשרי‬–SID‫עבור‬ services ‫ההפעלה‬ ‫מערכת‬ ‫תהליכי‬ ‫הפעלת‬‫על‬ ‫בעיקר‬ ‫מתבססת‬LocalSystem‫מאפשר‬ ‫אשר‬ ‫מנגנון‬ ‫על‬ ‫מתבססת‬ ‫מתוך‬ ‫חלקיות‬ ‫הרשאות‬ ‫ביזור‬ ‫ה‬ ‫הרשאות‬–LocalSystem/ LocalService/NetworkService ‫ב‬ ‫שימוש‬–write restricted token‫קיים‬ ‫לא‬‫אפשרי‬ ‫ה‬ ‫גישת‬ ‫הגבלת‬-services‫למשאבי‬ ‫הרשת‬ ‫חלקי‬ ‫באופן‬ ‫רק‬ ‫אפשרית‬(inbound) ,‫ה‬ ‫בהפעלת‬ ‫מותנית‬–windows firewall ‫ה‬ ‫מרבית‬–windows services ‫למשאבי‬ ‫לגישה‬ ‫ביחס‬ ‫מוקשחים‬ ‫תלות‬ ‫ללא‬ ‫אוטומטי‬ ‫באופן‬ ‫הרשת‬ ‫ה‬ ‫בהפעלת‬–windows firewall, ‫עבור‬app services‫להגדיר‬ ‫ניתן‬ ‫באמצעות‬ ‫הקשחה‬ ‫חוקי‬ ‫עבורם‬API
  • 7. Combined firewall and IPsec managementFirewall rules become more intelligentPolicy-based networking
  • 8. ‫נושא‬Windows XP / Windows Server 2003Windows Vista / Windows Server 2008 ‫נכנסת‬ ‫נתונים‬ ‫תעבורת‬ ‫לגבי‬ ‫מדיניות‬ ‫אכיפת‬ (inbound) ‫אפשרית‬‫אפשרית‬ ‫יוצאת‬ ‫נתונים‬ ‫תעבורת‬ ‫לגבי‬ ‫מדיניות‬ ‫אכיפת‬ (outbound) ‫אפשרית‬ ‫לא‬‫אפשרית‬ ‫העברת‬ ‫אבטחת‬ ‫תצורת‬ ‫לגבי‬ ‫מדיניות‬ ‫אכיפת‬ ‫נתונים‬ ‫ה‬ ‫ברמת‬ ‫נתמך‬ ‫לא‬–firewall,‫למימוש‬ ‫אפשרי‬ ‫ע‬"‫ה‬ ‫י‬–IP security policies(GPO) ‫באמצעות‬ ‫אפשרית‬IPSEC ‫בדומיין‬ ‫לחברות‬ ‫בהתאם‬ ‫מדיניות‬ ‫אכיפת‬‫אפשרית‬ ‫לא‬‫אפשרית‬ ‫משתמש‬ ‫לשם‬ ‫בהתאם‬ ‫מדיניות‬ ‫אכיפת‬/‫שם‬ ‫מחשב‬ ‫אפשרית‬ ‫לא‬‫אפשרית‬ ‫המחשב‬ ‫אליה‬ ‫לרשת‬ ‫בהתאם‬ ‫מדיניות‬ ‫אכיפת‬ ‫מחובר‬ ‫אפשרית‬ ‫לא‬‫אפשרית‬–‫קיימים‬3‫פרופילים‬ (public/private/domain) ‫ב‬ ‫תמיכה‬–windows service hardening‫קיימת‬ ‫לא‬‫קיימת‬ ‫באמצעות‬ ‫חוקים‬ ‫בהחלת‬ ‫תמיכה‬GPO‫מה‬ ‫שונה‬ ‫הממשק‬ ‫אבל‬ ‫אפשרית‬–windows firewall MMC ‫ל‬ ‫לחלוטין‬ ‫זהה‬ ‫באופן‬ ‫אפשרית‬–windows firewall advanced security MMC ‫עקיפה‬ ‫חוקי‬ ‫קביעת‬(bypass)‫תקשורת‬ ‫עבור‬ ‫נכנסת‬/‫ספציפיים‬ ‫ממחשבים‬ ‫יוצאת‬ ‫חלקי‬ ‫באופן‬ ‫אפשרית‬‫אפשרית‬ ‫אובייקטים‬ ‫סמך‬ ‫על‬ ‫בהתאם‬ ‫חוקים‬ ‫קביעת‬ ‫מה‬–Active Directory ‫אפשרית‬ ‫לא‬‫אפשרית‬ ‫ב‬ ‫תמיכה‬–IPv6‫דורשת‬ ‫אבל‬ ‫אפשרית‬SP(‫עבור‬Windows XP – SP2,‫עבור‬Windows Server 2003 – SP1) ‫ב‬ ‫צורך‬ ‫ללא‬ ‫אפשרית‬–SP
  • 9. Only a subset of the executable files and DLLs installed No GUI interface installed 9 available Server Roles Can be managed with remote tools
  • 11. • Arsenal of Admin Tools • Delegated Management • Secure Remote Management • Shared Config for Web Farms Better Tools Intuitive, Task Oriented GUI .NET Management API Unified WMI Provider for IIS/ASP.NET Powerful Command Line Support Rich Runtime State Information Automatic Failure Tracing & Logging Site Owner Web.config XML Administrator Internet Manage Remotely Secure HTTPS AppHost.config XML Shared Config Shared App Hosting Web FarmApp
  • 12. Group Policy allows central encryption policy and provides Branch Office protection Provides data protection, even when the system is in unauthorized hands or is running a different or exploiting Operating System Uses a v1.2 TPM or USB flash drive for key storage Full Volume Encryption Key (FVEK)Encryption Policy
  • 14. AD RMS protects access to an organization’s digital files AD RMS in Windows Server 2008 includes several new features Improved installation and administration experience Self-enrollment of the AD RMS cluster Integration with AD Federation Services New AD RMS administrative roles Information Author The Recipient
  • 16.
  • 17.
  • 18.
  • 19.
  • 20. Add users with Read and Change permissions Verify aliases & DLs via AD Add advanced permission s
  • 21. Set expiration date Enable print, copy permissions Add/remove additional users Contact for permission requests Enable viewing via RMA
  • 23.
  • 24.
  • 25.
  • 26.
  • 27.
  • 28.
  • 29.
  • 30.
  • 31.
  • 32.
  • 33. AD FS provides an identity access solution Deploy federation servers in multiple organizations to facilitate business-to- business (B2B) transactions AD FS provides a Web- based, SSO solution AD FS interoperates with other security products that support the Web Services Architecture AD FS improved in Windows Server 2008 Web Server Account Federation Server Resource Federation Server LeadcomDario Federation Trust
  • 34. Main Office Branch Office Features Benefits RODC
  • 35. Enterprise PKI (PKIView) Online Certificate Status Protocol (OSCP) Network Device Enrollment Service Web Enrollment
  • 36. Cryptography Next Generation (CNG) Includes algorithms for encryption, digital signatures, key exchange, and hashing Supports cryptography in kernel mode Supports the current set of CryptoAPI 1.0 algorithms Support for elliptic curve cryptography (ECC) algorithms Perform basic cryptographic operations, such as creating hashes and encrypting and decrypting data
  • 37. ‫נושא‬CryptoAPICNG ‫סימטרית‬ ‫בהצפנה‬ ‫תמיכה‬ ‫א‬ ‫בהצפנה‬ ‫תמיכה‬-‫סימטרית‬ ‫ב‬ ‫תמיכה‬–hash ‫דיגיטליות‬ ‫בתעודות‬ ‫תמיכה‬‫באמצעות‬CAPI 2.0 ‫ארכיטקטורה‬CSPProtocol provider, CNG routers, CNG primitives ‫הצפנה‬ ‫במנגוני‬ ‫תמיכה‬legacy ‫אין‬ ‫אקראיים‬ ‫מספרים‬ ‫מחולל‬ ‫החלפת‬ ‫מחדש‬ ‫הקוד‬ ‫כתיבת‬ ‫דורשת‬‫בקוד‬ ‫מהותי‬ ‫שינוי‬ ‫ללא‬ ‫אפשרית‬ ‫חדשים‬ ‫אלגוריתמים‬ ‫שילוב‬ ‫אפשרי‬ ‫לא‬–‫קשיחה‬ ‫רשימה‬‫אפשרית‬–‫לעידכון‬ ‫וניתנת‬ ‫דינמית‬ ‫רשימה‬ ‫מרכזי‬ ‫ניהול‬ ‫מנגנון‬ ‫אין‬‫ה‬ ‫באמצעות‬ ‫אפשרי‬–key storage API ‫ב‬ ‫תמיכה‬–Suite B‫אין‬ ‫אלגוריתמים‬ CAPI 1.0 AES , SHA1 , SHA2, DSA, RSA,ECC,DH,ECDSA,ECDH,MD2,MD4,MD5, CAPI 1.0 ‫הפרטי‬ ‫המפתח‬ ‫הפרדת‬ ‫מהאפליקציה‬ ‫אפשרי‬ ‫לא‬‫באמצעות‬ ‫לביצוע‬ ‫אפשרי‬key isolation process ‫המפתחות‬ ‫שמירת‬ ‫מיקום‬ ‫הפרטיים‬ ‫ל‬ ‫מקושר‬–SID,‫תהליך‬ ‫על‬ ‫מקשה‬ ‫דומיינים‬ ‫בין‬ ‫מעבר‬ ‫ל‬ ‫מקושר‬ ‫לא‬–SID,‫בין‬ ‫מעבר‬ ‫תהליך‬ ‫לבצע‬ ‫קל‬ ‫דומיינים‬ ‫המפתחות‬ ‫שמירת‬ ‫פורמט‬‫סיומת‬REG,‫של‬ ‫מגבלה‬256‫תווים‬ ‫בשם‬ ‫סיומת‬ ‫ללא‬ ‫חדש‬ ‫פורמט‬REG,‫של‬ ‫מגבלה‬512‫תווים‬ ‫בשם‬
  • 38. Internet Perimeter Network Corporate Network Remote/ Mobile User Terminal Services Gateway Network Policy Server Active Directory DC Tunnels RDP over HTTPs Strips off RDP / HTTPs Terminal Servers and other RDP Hosts RDP traffic passed to TS Internet
  • 39. Remediation Servers Example: Patch Restricted Network Windows Client Policy compliant NPS DHCP, VPN Switch/Router Policy Servers such as: Patch, AV Corporate Network Not policy compliant What is Network Access Protection? Health Policy Validation Health Policy Compliance Ability to Provide Limited Access Enhanced Security Increased Business Value
  • 40. 1 Remediation Servers Example: Patch Restricted Network 1 Windows Client 2 2 DHCP, VPN or Switch/Router relays health status to Microsoft Network Policy Server (RADIUS) 3 3 Network Policy Server (NPS) validates against IT- defined health policy 4 If not policy compliant, client is put in a restricted VLAN and given access to fix up resources to download patches, configurations, signatures (Repeat 1 - 4) Not policy compliant 5 If policy compliant, client is granted full access to corporate network Policy compliant NPS DHCP, VPN Switch/Router 4 Policy Servers such as: Patch, AV Corporate Network 5 Client requests access to network and presents current health state
  • 41. 41 Internet Protocol security (IPsec)-protected communications IEEE 802.1X-authenticated network connections Remote access virtual private network (VPN) connections Dynamic Host Configuration Protocol (DHCP) configuration
  • 42. Policy based – was network access allowed • Health based - % compliant per SHA
  • 44. Amit Gatenyo Infrastructure & Security Manager Dario IT Solutions ltd amit.g@dario.co.il 054-2492499