On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

September 21st, 2007

Microsoft hacker summit tackles security veil of virtualization

Posted by Ryan Naraine @ 7:46 am

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, Metasploit, Microsoft, Pen testing, Punditocracy, Responsible disclosure, Rootkits, Spam and Phishing, Viruses and Worms, Vulnerability research, Windows Vista, Zero-day attacks

Tags: Microsoft Corp., Virtualization, Storage Management, Utility Computing, Rootkits, Hardware, Storage, Security, Spyware, Adware & Malware, Ryan Naraine

Microsoft hacker summit tackles security veil of virtualizationThe Fall edition of Microsoft’s Blue Hat hacker summit will kick off next week with a heavy focus on piercing the security veil of virtualization and process isolation.

At Blue Hat v6, scheduled for September 27-28 in Redmond, external security researchers and internal Microsoft software engineers are expected to extend the debate over the risks of virtualization.

Researchers are divided over whether hypervisor rootkits presents a realistic threat. Joanna Rutkowska, for example, claims that malware can be made “100% undetectable” but, at this year’s Black Hat Briefings, a group of her peers openly challenged that assertion, insisting that virtual machine rootkits are rather easy to detect.

Microsoft has a vested stake in the virtualization/security debate. Earlier this year, the company canceled plans to tweak Windows Vista’s licensing around virtualization, citing potential security risks. Redmond’s explanation was that “security researchers have shown hardware virtualization technology to be exploitable by malware” and claimed Vista required an advanced level of know-how to thwart such virtualization exploits.

[ SEE: Let users virtualize Vista because hypervisor rootkits are no threat ]

According to Microsoft’s Andrew Cushman, the sixth edition of Blue Hat will also include talks on Windows Mobile and automated exploit creation using HD Moore’s Metasploit hacking tool.

There will also be a talk on a DNS pinning design issue that demonstrates how Internet Explorer can turn into a VPN concentrator and presentations on Microsoft Office, Binary Instrumentation, Visualization and the Economics of Security.

The full speaker and topic list is not yet available.  The agenda and speaker list has slipped out. It features several regulars on the infosec conference circuit, including IOActive’s Dan Kaminsky, Roberto Preatoni from the WabiSabiLabi vulnerability auction siteMark Russinovich, Leviathan’s Matt Miller, Sourcefire’s Lurene ‘Pusscat’ Grenier and Jeff Forristal of SPI Dynamics.

* Image via Hugh McLeod’s gapingvoid.com.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Talkback

Add your opinion

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More