Microsoft reaches out at China hacker conference
- 20 August, 2009 00:02
- Comments 1
Microsoft shared the stage with Chinese security researchers at a Beijing hacker conference on Wednesday, aiming to build ties in a country that produces a growing number of threats to Microsoft products.
John Lambert, a team head at the Microsoft Security Engineering Center, spoke to an audience of a few hundred people about security features in Microsoft products and tools used by the company to find vulnerabilities in its software.
Microsoft has worked to build contacts with security researchers worldwide, but the language barrier and low attendance by Chinese experts at overseas conferences make the country's security circles harder to access, Lambert said.
Important security research increasingly comes out of China, but is often presented in Chinese, he said.
Microsoft was a sponsor of the Beijing forum, called XCon, and Lambert said the company would consider attending other security conferences in China where skilled researchers gather.
Microsoft also wants to educate more Chinese software developers on security issues to shield Windows and Internet Explorer users from vulnerabilities in third-party programs, said Lambert.
China produces a growing amount of malware, which usually targets domestic users but is sometimes aimed abroad as well. Two zero-days, or previously unknown vulnerabilities, that were found this year in Internet Explorer appeared to come out of China, said Lambert.
Other speakers at the forum shared tactics that could be used to find or exploit vulnerabilities in software, but researchers in the audience said Microsoft measures had made attacking its programs with exploits more difficult.
"There may still be vulnerabilities, but it's harder to exploit them," said one researcher. He cited one obstacle as address space layout randomization, a function included in Windows Vista that rearranges the positions of key system code when a PC restarts.
But attackers searching for vulnerabilities in Microsoft products are as active as ever, he said.
One Chinese researcher at the forum demonstrated a tool for fuzz testing of software, a technique used by software vendors and attackers that involves feeding a program invalid data inputs to see what causes a crash. The tool recorded program activity during a crash to help a tester pinpoint its cause. One speaker duo discussed ways to trace the code changes between original and updated versions of a program and another speaker presented tactics used in cross-site scripting, a vulnerability that allows malicious code to be injected to Web sites.
Forum organizers at first said reporting on the event was banned because it dealt with sensitive topics.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Swedish e-commerce startup's execs linked to NYC sex crime
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Automating Your Processes to Outperform Your Competition
Welcome to Volume Three of the “Intelligent Guide to Enterprise BPM.” Get ready for an education in automation—Process Automation, that is. This white paper goes into detail about the Process Automation entry point into an Enterprise Business Process Management (BPM) program. Read on to learn how Process Automation opens up new ways to help your business do things faster—like open up a new sales channel or deliver customer orders. Discover how Process Automation enables your business to run smoother and consistently in an orchestrated way. With a true Enterprise BPM solution, you can automate newly designed processes far easier than starting from scratch. -
Teleworking made simple—and secure—with desktop virtualisation technology
Businesses of all sizes are increasingly focused on creating flexible work environments and offering telework options for employees. By administering policies and providing the technical capability for employees to work remotely, these companies can improve job satisfaction and worker attraction and retention. This paper explores the implementation of teleworking based on a foundation of desktop and server virtualisation. -
Server and Storage Optimization Techniques
By meeting the requirements to deploy new applications and support a larger number of internal and external customers, IT organizations are facing a space, power, and cooling crunch. Read on.
-
Objects, Abstraction, and Data Structures Using C++ Desktop Edition
-
AutoCAD 2009 & AutoCAD LT 2009 Bible
-
Excel for Dummies, 2nd Edition
-
Programming Java 2 Micro Edition on Symbian OS - a Developer's Guide to Midp 2.0
-
Assembly Language Step-by-step, Second Edition
-
Architecture of Computer Hardware and System Software
-
Mastering System Center Operations Manager 2007
-
Webex Web Meetings for Dummies
-
PC Magazine Digital SLR Photography Solutions








Comments
Laguna
Познавательно
Красота — это своего рода гениальность, даже больше, чем гениальность, ибо она в объяснении не нуждается.
Post new comment