Microsoft defends PCs, post network penetration

News
Mar 2, 20162 mins

Because sometimes bad things happen, Microsoft is bringing the security fight inside.

This week at the RSA security conference, Microsoft announced the succinctly named Windows Defender Advanced Threat Detection product. The solutions (which really needs a better or at least shorter name) is focused on helping an organization’s IT department detect threats to Windows 10 machines after the perimeter network has been penetrated. This is an important and pragmatic recognition of the fact that despite most solutions focusing on perimeter security, sometimes the outside line gets broken and hackers find a way in.

The solution allows security teams to decide which individual Windows 10 they monitor and is based on Microsoft’s Security Graph, a machine learning tool that compares the massive pool of security information that Microsoft gathers from around the world, with the live state of machines running on the network. When an anomaly is detected, the system informs the IT department who can then decide what to do.

This introduces a degree of “fuzzy logic” into the system whereby the probability of a security issue, rather than an absolute certainty that something has gone wrong is generated. It then defers to a human operator to make a final decision – a kind of a “best of both worlds” mix of automation and human instinct. 

Alas, this tool is only designed for Windows 10 and doesn’t work with either previous versions of Windows or other operating systems. In testing the solution has been deployed across 500,000 end-user devices.

“We’re seeing increasingly brazen cyber attacks. Cybercriminals are well organized with an alarming emergence of state-sponsored attacks, cyber-espionage and cyber terror. Even with the best defense, sophisticated attackers are using social engineering and zero-day vulnerabilities to break-in to corporate networks,”  Terry Myerson, Microsoft’s executive vice president of the windows and device group, wrote in a blog post describing the new product.

Interestingly post-breach activity is an increasingly important part of the security toolbox – expect more vendors to focus on this part of the security lifecycle as the perimeter security space becomes increasingly busy.

benkepes

Ben Kepes is a technology evangelist, an investor, a commentator and a business adviser. His business interests include a diverse range of industries from manufacturing to property to technology. As a technology commentator he has a broad presence both in the traditional media and extensively online. Ben covers the convergence of technology, mobile, ubiquity and agility, all enabled by the cloud. His areas of interest extend to aviation technology, enterprise software, software integration, financial/accounting software, platforms and infrastructure as well as articulating technology simply for everyday users.

He is a globally recognized subject matter expert with an extensive following across multiple channels. His commentary has been published on Forbes, ReadWriteWeb, GigaOm, The Guardian and a wide variety of publications – both print and online. Often included in lists of the most influential technology thinkers globally, Ben is also an active member of the Clouderati, a global group of cloud thought leaders and is in demand as a speaker at conferences and events all around the world.

As organizations react to the demands for more flexible working environments, the impacts of the economic downturn and the existence of multiple form-factor devices and ubiquitous connectivity, Cloud computing stands alone as the technology paradigm that enables the convergence of those trends -- Ben’s insight into these factors has helped organizations large and small, buy-side and sell-side, to navigate a challenging path from the old paradigm to the new one.

Ben is passionate about technology as an enabler and enjoys exploring that theme in various settings.

The opinions expressed in this blog are those of Ben Kepes and do not necessarily represent those of IDG Communications, Inc., its parent, subsidiary or affiliated companies.

More from this author