NEWS / WINDOWS

Microsoft’s Attack Surface Analyzer tool released

| by tech2 News Staff | Windows

Last year, Microsoft had announced the beta version to its Attack Surface Analyzer tool. Now the beta stage is complete as Attack Surface Analyzer 1.0 is available for download. The purpose of this tool is to help software developers, independent software vendors (ISVs) and IT professionals better understand changes in Windows systems’ attack surface resulting from the installation of new applications. Since the launch of Attack Surface Analyzer, the company has received positive feedback about the value it has provided to customers. Attack Surface Analyzer tool can be downloaded here

 

This release includes performance enhancements and bug fixes to improve the user experience. Through improvements in the code, Microsoft was able to reduce the number of false positives and improve Graphic User Interface performance. This release also includes documentation and guidance to improve ease of use.   

COVER

Attack Surface Analyzer released

 

 

The Attack Surface Analyzer tool is designed to assist independent software vendors (ISVs) and other software developers during the verification phase of the Microsoft Security Development Lifecycle (SDL) as they evaluate the changes their software makes to the attack surface of a computer. As Attack Surface Analyzer does not require source code or symbol access, IT professionals and security auditors can also use the tool to gain a better understanding of the aggregate attack surface change that may result from the introduction of line-of-business (LOB) applications to the Windows platform. 

 

The Attack Surface Analyzer enables:

  • Developers to view changes in the attack surface resulting from the introduction of their code on to the Windows platform
  • IT Professionals to assess the aggregate attack surface change by the installation of an organization's line of business applications
  • IT Security Auditors to evaluate the risk of a particular piece of software installed on the Windows platform during threat risk reviews
  • IT Security Incident Responders to gain a better understanding of the state of a systems security during investigations (if a baseline scan was taken of the system during the deployment phase)

 

Unlike many tools that analyze a system based on signatures or known vulnerabilities, Attack Surface Analyzer looks for classes of security weaknesses Microsoft has seen when applications are installed on the Windows operating system, and it highlights these as issues. The tool also gives an overview of changes to the system that Microsoft considers important to the security of the platform and highlights these changes in the attack surface report. Some of the checks performed by the tool include analysis of changed or newly added files, registry keys, services, Microsoft ActiveX controls, listening ports and other parameters that affect a computer's attack surface.

 

The tool has a stand-alone wizard to help guide users through the scanning and analysis process; a command-line version supports automation and older versions of Windows, and assists IT professionals as they integrate the tool with existing enterprise management tools.

Tags: Microsoft Attack Surface Analyzer , Microsoft , Attack Surface Analyzer download , Attack Surface Analyzer x86 , Attack Surface Analyzer x64 , Attack Surface Analyzer features , Attack Surface Analyzer antivirus

HNNCast.ToolTime.2011.01.21

24 Jan, 2011, 10:10 am IST

HNNCast.ToolTime.2011.01.21

 


Leaked Images, Availability, Pricing,
Specs, Pre-order

How to: Bring your Windows operating system up to speed

How to: Bring your Windows operating system up to speed

We bring you a handful of useful tips and tricks to get more out of your...

By Team Tech2

Office 2013 vs Office 365: Should you buy or subscribe?

Office 2013 vs Office 365: Should you buy or subscribe?

Pirated or legal, the vast majority of us use Microsoft Office. It’s...

By Jamshed Avari

Being anonymous on the web

Being anonymous on the web

Methods to implement to hide your IP address whilst on the Internet

By Francis D'sa

MORE FEATURES

LAVA iris 455 Review

Rupali Panchadhaye

Wed May 22, 15:03:37

MORE DISCUSSIONS