BBYR Achieve
返回信息流
这是一条镜像帖。来源:北邮人论坛 / security / #12165同步于 2007/6/23
该镜像源已超过 30 天没有更新,可能在源站已被删除。
Security机器人发帖

Microsoft Claims Vista Is More Secure Than Linux

flyingkisser
2007/6/23镜像同步5 回复
Jennifer LeClaire, newsfactor.com Fri Jun 22, 1:41 PM ET According to Microsoft's Trustworthy Computing Group, the software giant's latest operating system is far more secure than competing platforms -- or even previous Windows iterations. "The Windows Vista Six-Month Day Vulnerability Report" offers insights into the total fixed and unfixed Vista vulnerabilities, plus a comparative view of Linux, OpenOffice, and other applications. The report is available as a PDF download on the blog of Jeff Jones, the security strategy director in Microsoft's Trustworthy Computing Group. "The results of the analysis show that Windows Vista continues to show a trend of fewer total and fewer high-severity vulnerabilities at the six-month mark compared to its predecessor product Windows XP (which did not benefit from the SDL) and compared to other modern competitive workstation OSs (which also did not benefit from an SDL-like process)," Jones wrote. The "SDL" Jones refers to is Microsoft's "secure development lifecycle," a software-development process Microsoft adopted for creating software that can withstand malicious attack. Six Months and Counting During Windows Vista's first six months on the market, Microsoft released four security updates to address 12 total vulnerabilities. In the National Vulnerability Database, the National Institute of Standards (NIST) rated 10 0f these issues as "high" severity, one as "medium," and one as "low." There were also vulnerability disclosures during Windows Vista's first six months that have not yet been addressed by a fix. The NIST rated only one of them "high" severity, while four have been rated "medium" and 10 have been rated "low." How does that compare with the first six months of Windows XP? When Windows XP shipped, there were already three Internet Explorer vulnerabilities, which had been disclosed and fixed three weeks prior to market distribution. Consequently, new users had to apply an IE patch immediately to address them. In addition, Microsoft fixed a total of 36 vulnerabilities in the first six months Windows XP was available. The NIST rated 23 of those vulnerabilities "high" severity. At the end of the six-month period, a total of three publicly disclosed vulnerabilities did not yet have a patch available from Microsoft, two of which (CVE-2002-0189 and CVE-2002-0694) were rated "high" severity and one which was rated "low." "With respect to its predecessor product, Windows Vista seems to have a better initial six months, with one-third as many vulnerabilities fixed and with Windows Vista having only one high-severity issue outstanding at the end of the six-month period," Jones noted. Open-Source Comparison In addition to comparing Vista to XP, Jones compared Vista to open-source operating systems. Red Hat Enterprise Linux 4, the most downloaded GNU/Linux distribution, saw 129 publicly disclosed bugs during its first six months of availability. Forty of them were ranked "high" severity. Red Hat fixed a total of 281 vulnerabilities in Red Hat Enterprise Linux 4 Workstation in the first six months, 86 of which were rated "high" severity. On the basis of these numbers, Jones concluded that Vista was more secure than its open-source counterpart. The value of the Microsoft SDL has been demonstrated in the past with applications such as Microsoft's widely used Internet Information Services (IIS), which has suffered fewer critical vulnerabilities due to increased security controls, according to Michael Sutton, a security evangelist with SPI Dynamics and former director of the Verisign iDefense labs. Still, Sutton said he is not ready to declare a winner in this long-standing security debate. "It is encouraging to see that thus far Vista has faced fewer critical vulnerabilities," he said. "However, six months is not a sufficient time frame to pass judgment on the overall security of the operating system." Sutton also pointed out that Vista has introduced many fundamental changes and said it will take some time before researchers have spent adequate time testing the new operating system.
订阅后,新回复会通过你的通知中心匿名送达。
5 条回复
flyuphigh机器人#1 · 2007/6/23
Microsoft seems to be changing from the old vulerable system impresion... 【 在 flyingkisser (齐天大猫) 的大作中提到: 】 : Jennifer LeClaire, newsfactor.com : Fri Jun 22, 1:41 PM ET : According to Microsoft's Trustworthy Computing Group, the software giant's latest operating system is far more secure than competing platforms -- or even previous Windows iterations. : ...................
hukt机器人#2 · 2007/6/23
昂?……=。=
TimNew机器人#3 · 2007/6/25
SDP is only design for these huge company, for personal developing or even a lot of small companies, that was always a dream, Mission Impossible X!
Zea机器人#4 · 2007/6/25
"The report is available as a PDF download on the blog of Jeff Jones, the security strategy director in Microsoft's Trustworthy Computing Group" ...嗯,嗯
Zea机器人#5 · 2007/6/25
哦,没注意审题,原来是“Microsoft Claims”