Viewfinity Uses a Kernel Layer Approach when Managing Administrative Privileges

by Alex Shoykhet 2. June 2011 15:24

There's been buzz recently about various technology methods for privilege management on Windows PCs.  There isn't any doubt as to the proper architecture method. Viewfinity maintains that managing privileges at the kernel level is the most technologically sound approach for controlling least privileges at the desktop level.  Kernel driver is the industry standard method used by most anti-virus vendors, most DLP products, and is the method which should be used for security products such as privilege elevation management. The technology is complicated, but endorsed and regulated by Microsoft. So called “elevation” of drivers is assigned and maintained by Microsoft.  Software vendors that took a short cut in this advanced field went with a simpler, more amateur approach: user mode hooking technology which  is not officially supported by Microsoft, as clearly stated in the excerpt from Microsoft’s documentation: 

Straight from the README.TXT of API hooking, or the Detours library

4.5. SUPPORT FOR DETECTION OF DETOURED PROCESSES:
=================================================
Detours loads the detoured.dll shared library stub into any process which has
been modified by the insertion of a detour. This allows the Microsoft Customer
Support Services (CSS) and the Microsoft Online Crash Analysis (OCA) teams to
quickly and accurately determine that the behavior of a process has been
altered by a detour. CSS does not provide customer assistance on detoured
products.
  

Comments

Add comment


 

  Country flag

biuquote
  • Comment
  • Preview
Loading



Powered by BlogEngine.NET 1.4.5.0
Theme by Mads Kristensen

Calendar

<<  May 2012  >>
MoTuWeThFrSaSu
30123456
78910111213
14151617181920
21222324252627
28293031123
45678910

View posts in large calendar

About Viewfinity

Viewfinity provides privilege management and application control for desktops, laptops and servers, empowering enterprises to meet compliance mandates, reduce security risks, and lower IT costs. Many enterprises are implementing least privileges to add a solid layer of defense for desktop environments, further protecting against malware and Advanced Persistent Threats. Viewfinity allows IT Administrators to create and enforce default-deny and elevated permission policies for endpoint access to applications and desktop functions by controlling user rights for desktops and mobile laptop/netbook users. For more information, visit www.viewfinity.com.

Follow us on Twitter: viewfinity
Find us on LinkedIn: www.linkedin.com/companies/viewfinity
Become a fan on Facebook: www.viewfinity.com/facebook