New version of Intel's vPro includes improved firewall for sniffing out viruses and worms
Intel is readying the second version of its chip-based vPro security technology for the desktop. The initial version debuted in September amid support from partners Symantec, Altiris and others.
Intel is readying the second version of its chip-based vPro security technology for the desktop. The initial version debuted in September amid support from partners Symantec, Altiris and others.
According to Mike Ferron-Jones, director of marketing in Intel’s digital office platforms division, the next generation of vPro, expected out in the second half of 2007, will be based on Intel’s Core 2 Duo Processor E6x50 and Q35 Express Chipset, and will be backward compatible with the vPro sold today.
Like today’s vPro, the new version (code-named Weybridge) will allow chip-based firewall filtering and remote management. But the management technology will be based on a new specification soon to be announced by the Desktop Mobile Working Group as well as the industry standard called Web Services Management. In addition, the built-in firewall in the upcoming Weybridge version will come preprogrammed to monitor outbound traffic to recognize abnormal patterns that suggest virus or worm activity.
“We’ll add some preconfigured programming for rudimentary filtering that’s helpful in preventing worm or virus attacks,” says Ferron-Jones, noting there will be options to generate alerts to management consoles or cut off network access of infected machines. Systems administrators can de-activate the feature if they don’t want this type of policy. In the current version of vPro, setting firewall filters is wholly based on third-party applications.
The Weybridge version will also be able to make use of what Intel calls its Trusted Extension Technology, which is a way to measure software through cryptographic hash algorithms that produce a kind of digital fingerprint to check its veracity. Intel referred to this capability in the past by the code-name LaGrande.
The Trusted Extension Technology in the next-generation vPro will be able to carry out this hash-based software measurement by working in conjunction with desktops using the microcontroller Trusted Platform Module Version 1.2 designed under the aegis of the industry-standards organization Trusted Computing Group.
Ferron-Jones says Intel’s focus in developing the Trusted Extension Technology was primarily to prevent rootkits from compromising software-based virtual-machine monitors, such as those from Microsoft, VMware and Parallels. These virtual-machine monitors allow what the industry calls multiple virtual appliances to work on the operating system. “We want to prevent attacks to compromise the virtual-machine monitor,” says Ferron-Jones.
While Intel couldn’t release exact sales figures for the first vPro that shipped last September, Ferron-Jones says it’s being well-received, with customers that include BMW, EDS and ING.




