Feeds

Microsoft refreshes secure developer software tools

Attack Surface Analyzer makes its debut

SANS - Survey on application security programs

Microsoft has released a new software tool to help developers write secure applications by highlighting the system changes created when their wares are installed on Windows machines.

The Attack Surface Analyzer, released on Tuesday, is a free verification tool that analyzes the changes in system state, runtime parameters and securable objects in the Windows operating system. The tool, which was released as part of Microsoft's Secure Development Lifecycle, takes snapshots of a system and compares the results before and after an app is installed. It then identifies resulting classes of security weaknesses.

“The tool also gives an overview of the changes to the system Microsoft considers important to the security of the platform and highlights these in the attack surface report,” David Ladd, Microsoft's principal security program manager, blogged. Among the checks performed are analysis of changed or newly added files, registry keys, services, ActiveX controls, listening ports, and access control lists. It's available for free, for now as a beta so that Microsoft can collect feedback from users.

Attack Surface Analyzer was one of several security tools Microsoft released at this week's Black Hat Security Conference in Washington, DC. Redmond also published the next version of its SDL Threat Modeling Tool that's used to assess whether applications under development meet security and privacy guidelines. It now works with Microsoft Visio 2010. More details are here.

The software company also released version 1.2 of the SDL Binscope Binary Analyzer, a verification tool that analyzes binaries on a project-wide level to insure they comply with SDL requirements.

The new offerings add to a growing roster of free security apps Microsoft makes available for free to developers. Other tools include version 2 of EMET, short for Enhanced Mitigation Experience Toolkit. It is used to add security measures such a Data Execution Prevention and Address Space Layout Randomization to older applications and operating systems, such as Internet Explorer 6 and Windows XP. Other apps include the Microsoft Solutions Framework, !exploitable Crash Analyzer, and the Microsoft MiniFuzz fuzzer tool.

Tuesday's additions come as vulnerability tracking service Secunia reported that failure to apply third-party patches – as opposed to updates from Microsoft – is "almost exclusively" responsible for the growing exposure of Windows machines to security threats. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
NSA denies it knew about and USED Heartbleed encryption flaw for TWO YEARS
Agency forgets it exists to protect communications, not just spy on them
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.