Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

11/16/2016
03:15 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Windows 10 Updates Target Ransomware Threats

Microsoft strengthens Windows 10 security with measures to prevent, detect, and respond to ransomware attacks. But they are only useful for businesses using all the right tools.

Ransomware is a priority in Microsoft's Windows 10 Anniversary Update, a major upgrade to the OS released one year after its public launch.

The bundle includes security built to protect businesses by discovering and addressing ransomware threats. According to Microsoft, the number of ransomware variants has more than doubled  in the last 12 months. 

"Ransomware is what I would call the quick-hit, low-hanging fruit type of opportunity for a threat actor," said Chris Goettl, senior product manager for the security team at Landesk. "You can distribute it to a wider market, you can charge an amount likely to be easily paid … you can diversify it pretty well."

To fight the growing threat, Microsoft has added new security measures to different aspects of Windows 10. These updates were organized into three categories for ransomware prevention, detection, and response.

While the additions improve on ransomware defense in Windows 10, they won't help users who don't have various components of the Microsoft suite, Goettl noted. Some products, like Microsoft Edge and Windows Defender, were strengthened in the Anniversary Updated but aren't as frequently used among businesses.

For example, consider the Edge browser. It was updated so Adobe Flash Player, a plugin frequently used by exploit writers, will run in an isolated container. Edge has also been adjusted so an exploit running in the browser cannot execute another program; this blocks malware from silently downloading and executing on users' systems.

Edge may be safer, but the added protection means little if people don't use it. Microsoft's new browser is not as popular as competitors Chrome and Firefox.

"When Microsoft says they've hardened the browser, I have to then adopt that browser and make sure all my users are using that browser," said Goettl. "You're forcing users to use a specific type of technology, but they're going to use what they like to use."

In other preventive updates, Microsoft improved its email services to block ransomware, developed machine learning models to catch ransomware stored in file attachments, and created a faster signature delivery channel to quickly update Windows Defender running in email.

To accelerate ransomware detection, Microsoft improved cloud protection in Windows Defender and improved behavioral heuristics. This way, the tool can determine if a file is performing ransomware-related activities, and quickly take action.

Windows Defender is getting better with behavioral heuristics, said Goettl, and businesses should have something to detect ransomware. However, the signature-based technology limits its ability to address threats as quickly as other platforms. There are several non-signature-based protection platforms, and many companies won't choose Windows Defender if they're seeking the best value for their dollars, he explained.

In the event these defensive layers fail, Microsoft upped ransomware response with Windows Defender Advanced Threat Protection (ATP) so companies can detect and address attacks. The tool combines security events gathered from machines and sends alerts to enterprise security teams.

When Windows Defender ATP is combined with Office 365 ATP, the two share signals to give a holistic view of enterprise attacks. This gives a higher level of protection, said Goettl, but organizations who want it will have to adopt the full Microsoft model including Windows 10, Office 365 ATP, and Windows Defender. Many businesses are adopting Office 365, but this doesn't necessarily mean they're adopting Office 365 ATP.

Microsoft's updates arrive as businesses are struggling to mitigate the risk of ransomware. It's difficult to safeguard against these types of attacks, which trick individual users by mimicking things they know and trust.

"Ransomware is one of the bigger challenges facing us today," said Goettl, noting how attackers will continue to use the opportunity for quick, repetitive payouts. "It's here to stay, it's not going anywhere, and it's going to continue to be a threat to our environments."

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JimH747
50%
50%
JimH747,
User Rank: Apprentice
11/22/2016 | 9:10:33 AM
About time
It's great that Microsoft is taking a proactive approach. I've been relying on solutions like RollBack Rx and Comodo Time Machine. Both good programs, but Microsoft needed to start picking up the slack at some point.
JimH747
50%
50%
JimH747,
User Rank: Apprentice
11/22/2016 | 9:10:15 AM
About time
It's great that Microsoft is taking a proactive approach. I've been relying on solutions like RollBack Rx and Comodo Time Machine. Both good programs, but Microsoft needed to start picking up the slack at some point.
When It Comes To Security Tools, More Isn't More
Lamont Orange, Chief Information Security Officer at Netskope,  1/11/2021
US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security
Seth Rosenblatt, Contributing Writer,  1/11/2021
IoT Vendor Ubiquiti Suffers Data Breach
Dark Reading Staff 1/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25533
PUBLISHED: 2021-01-15
An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct ...
CVE-2021-3162
PUBLISHED: 2021-01-15
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
CVE-2021-21242
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or a...
CVE-2021-21245
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbitrary file upload which can be used to u...
CVE-2021-21246
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the `/users/` endpoint there are no security checks enforced so it is possible to retrieve ar...