




已閱讀5頁,還剩141頁未讀, 繼續(xù)免費(fèi)閱讀
版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡介
第一篇區(qū)塊篇 IntegratedphoneandPDAPrimarilydataviewingInteroperabilitywithOutlookandExchange NETCompactFrameworkASP NETmobilecontrols MobileDeviceSolutions Complexdocumentauthoring editingandreadingKeyboardcentricatthedeskKeyboardandmouseinputmethodsFull NETframeworkavailableCentrinoSolutions WindowsMobile WindowsXP Complexdocumentauthoring editingandactivereadingNotetakingandinkannotatingKeyboardcentricatthedesk penandkeyboardawayfromthedeskKeyboard mousepluspen ink andspeechinputmethodsFull NETframeworkpreinstalledPen ink handwritingandspeechrecognitionAPI sCentrinoSolutions ViewandsomedataentryIntegratedPDAwithphoneInteroperabilitywithOffice ExchangeandSQLServer NETCompactFrameworkASP NETmobilecontrolsIntelXscaleSolutions Windows CE One waynetworkInformationconsumption SmartPersonalObjects Smartphone PocketPCandPocketPCPhone NotebookPC TabletPC NetworkDefense HealthcheckupITchecks health ofclientNetworkAccessControlClientswhopassgetnetworkaccessClientswhodonotpassarefixedorblocked aka quarantined HealthmaintenanceQuarantinedclientscanbegivenaccesstoresourcestogethealthy FromHome VPN Dialup ReturningLaptops ConsultantsGuests UnhealthyDesktops MicrosoftBusinessSolutionsERPPositioning GuidingPrinciples Productive Integrated Extensible Capable ShortlearningcurveMinimaladministrativeoverhead ToolsintegratedtightlyAutomatescommontasks CustomizableforyourprocessIntegrateswith3rdpartytools RemotelyaccessibleRobust secure scalable StagingArchitecture Dataentry Test ApplicationCenter CommerceWeb Commerce CommerceData CommerceWeb Commerce CommerceData Application Center Application Center Data ACSCluster ACSCluster Clustercontroller Clustercontroller Data LiveCommunicationsClientRoadmap LC1 2ClientPlatformMultipartyIMP2PVoiceandVideoMPOPGroupsRoamingSIPsupportGPOpolicymanagement LC1 5ClientPlatformRollupofQFEsMPOPAdditionsFederation ArchivingNotificationHAAdditions LC2 0ClientPlatformNextgenerationofRTCexperiencesMorecoming 2003 2H04 Longhorn EnterpriseDeploymentUpdate Internet Firewall Firewall Firewall RuntimeServers CorporateLAN InternalServers Crawl Search LoadBalancedWeb InfrastructureServers DevelopmentServers TestServers BusinessDataServers BusinessUsers DatabaseandStagingServers StagingServers DatabaseServers OfflineServers IndicatesStagedDataFlow Communicateandcollaborateinamoresecuremannerwithoutsacrificinginformationworkerproductivity WindowsXPSP2Blockvirusormaliciouscodeatthe pointofentry AtRisk TheSoftUnderbelly SecurityIssuesToday 1Source ForresterResearch2Source InformationWeek 26November20013Source Netcraftsummary4Source CERT 20035Source CSI FBIComputerCrimeandSecuritySurvey6Source ComputerSecurityInstitute CSI ComputerCrimeandSecuritySurvey20027Source CERT 20028Source GartnerGroup 14BdevicesontheInternetby2010135Mremoteusersby2005265 increaseindynamicWebsites3From2000to2002reportedincidentsrosefrom21 756to82 0944Nearly80percentof445respondentssurveyedsaidtheInternethasbecomeafrequentpointofattack upfrom57percentjustfouryearsago5 90 detectedsecuritybreaches685 detectedcomputerviruses695 ofallbreachesavoidablewithanalternativeconfiguration7Approximately70percentofallWebattacksoccurattheapplicationlayer8 ApplicationLayerAttacks IdentityTheftWebSiteDefacementUnauthorizedAccessModificationofData LogsandRecordsTheftofProprietaryInformationServiceDisruption Implications Compliance SarbanesOxleyGrammLeachBlilelyUSPatriotActHIPAAThePrivacyAct CA Basel2 EU DataProtectionAct EU LitigationFileSharingPiracyHRIssuesShareholderSuits CustomerImpact TypesOfSRPRules PathRuleComparespathoffilebeingruntoanallowedpathlistUsewhenyouhaveafolderwithmanyfilesforthesameapplicationEssentialinwhenSRPsarestrict HashRuleComparestheMD5orSHA1hashofafiletotheoneattemptedtoberunUsewhenyouwanttoallow prohibitacertainversionofafilefrombeingrun CertificateRuleChecksfordigitalsignatureonapplication i e Authenticode Usewhenyouwanttorestrictbothwin32applicationsandActiveXcontent InternetZoneRuleControlshowInternetZonescanbeaccessedUsewheninhighsecurityenvironmentstocontrolaccesstowebapplications SQLServer2005Themes Supportability Quality EnterpriseEnhancements Unified FlexibleAdministration PatchSolutions Prevention Readiness RecoveryEaseofuse PatchInstallsPatchinintegratedstep IntegratedDatabaseServicesandBusinessIntelligenceFlexibleinstallmanagement Addvaluetoone stepFailoverClusteringExpandedscriptingsupport TraditionalFirewalls Wideopentoadvancedattacks Performanceversussecuritytradeoff Limitedcapacityforgrowth Hardtomanage CodeRed NimdaSSL basedattacks SecurityiscomplexITisalreadyoverloaded BandwidthtooexpensiveToomanymovingparts NoteasilyupgradeableDon tscalewithbusiness ChoosingtheRightTypeofAssessment VulnerabilityScanningFocusesonknownweaknessesOfthethree requirestheleastexpertiseGenerallyeasytoautomate PenetrationTestingFocusesonknownandunknownweaknessesRequiresadvancedtechnicalexpertiseCarriestremendouslegalburdenincertaincountries organizations ITSecurityAuditsFocusesonsecuritypoliciesandproceduresOfthethree requiresthemostexpertiseWhendonerightisthemosteffectivetypeofassessment PerimeterSecurityEvolution Wideopentoadvancedattacks Application levelprotection Performanceversussecuritytradeoff Securityandperformance Limitedcapacityforgrowth Extensibilityandscalability Hardtomanage Easiertouse Theadvancedapplicationlayerfirewall VPNandWebcachesolutionthatenablescustomerstomaximizeITinvestmentsbyimprovingnetworksecurityandperformance AdvancedprotectionApplicationlayersecuritydesignedtoprotectMicrosoftapplications Fast secureaccessEmpowersyoutoconnectuserstorelevantinformationonyournetworkinacostefficientmanner EaseofuseEfficientlydeploy manage andenablenewusagescenarios Introducing ISAServer2004 Fast secureaccessEmpowersyoutoconnectuserstorelevantinfo onyournetwork ISAServer2004NewFeaturesContinuedcommitmenttointegration Enhancedarchitecture HighspeeddatatransportUtilizeslatestWindowsandPChardwareSSLbridgingunloadsdownstreamservers Webcache UpdatedpolicyrulesServecontentlocallyPre fetchcontentduringlowactivityperiods Internetaccesscontrol User andgroup basedWebusagepolicyExtensiblebythirdparties Comprehensiveauthentication NewsupportforRADIUSandRSASecurIDUser group basedaccesspolicyThirdpartyextensibility SystemServiceAccounts LocalServiceandNetworkServiceNopasswordtomanageRunswithonlyslightlymorepermissionsthanAuthenticatedUserLocalServicecannotauthenticateacrossthenetwork NetworkServiceauthenticatesasthecomputeraccount LocalSystemNopasswordtomanageBypassessecuritychecksUserAccountsRunwithlessprivilegethanLocalSystemStorespasswordasanLSAsecretCanbecomplextoconfigure What sNewWithIPSec ManagementIPSecurityMonitorCommand linemanagementwithNetshLogicaladdressesforlocalIPconfiguration SecurityStrongercryptographicmasterkey Diffie Hellman ComputerstartupsecurityPersistentpolicyforenhancedsecurityAbilitytoexcludethenameoftheCAfromcertificaterequestsBetterdefaultexemptionhandling InteroperabilityIPSecfunctionalityovernetworkaddresstranslation NAT ImprovedIPSecintegrationwithNetworkLoadBalancing ISAServer2004NewFeaturesNewmanagementtoolsanduserinterface Multi networkarchitecture UnlimitednetworkdefinitionsandtypesFirewallpolicyappliedtoalltrafficPernetworkroutingrelationships Networktemplatesandwizards WizardautomatesnwkroutingrelationshipsSupports5commonnetworktopologiesEasilycustomizedforsophisticatedscenarios Visualpolicyeditor Unifiedfirewall VPNpolicyw onerule baseDrag dropeditingw scenario drivenwizardsXML basedconfigurationimport export Enhancedtrouble shooting AllnewmonitoringdashboardReal timelogviewerContentsensitivetaskpanes EaseofUseEfficientlydeploy manage andenablenewusagescenarios HowToUseWindowsUpdate ToconfigureAutomaticUpdates SelectKeepmycomputeruptodate OpentheSystemapplicationinControlPanel 1 OntheAutomaticUpdatestab selecttheoptionyouwant 3 2 OfficeUpdate BenefitsLimitation SinglelocationforofficepatchesandupdatesEasytouseCanbeconfiguredtoupdateconsumerorenterprisesystems DoesnotsupportAutomaticUpdates updatingmustbeinitiatedmanually OfficeUpdateWebsite HowToUseOfficeUpdate Goto 1 ClickCheckforUpdates 2 InstalltheOfficeUpdateInstallationEngine ifnotalreadyinstalled 3 Selecttheupdatesyouwanttoinstall 4 ClickStartInstallation 5 HowToUseSUS OntheSUSserver ConfiguretheSUSserverathttp SUSAdmin OneachSUSclient ConfigureAutomaticUpdatesontheclienttousetheSUSserverUseGroupPolicy manuallyconfigureeachclient orusescripts SettheSUSserversynchronizationschedule Review test andapproveupdates 1 2 3 HowToUseMBSA DownloadandinstallMBSA onceonly 1 LaunchMBSA 2 Selectthecomputer s toscan 3 Selectrelevantoptions 4 ClickStartscan 5 ViewtheSecurityReport 6 SoftwareUpdateServiceDeploymentBestPractices 1 SoftwareUpdateServiceDeploymentBestPractices 2 HowToUseSMSToDeployPatches SMS MBSAIntegration MBSAintegrationincludedwithSMS2003andtheSUSFeaturePackforSMS2 0ScansSMSclientsformissingsecurityupdatesusingmbsacli exe hf MBSABenefits ScanssystemsforMissingsecuritypatchesPotentialconfigurationissuesWorkswithabroadrangeofMicrosoftsoftwareAllowsanadministratortocentrallyscanmultiplecomputerssimultaneouslyMBSAisafreetool andcanbedownloadedfrom MBSAConsiderations MBSAreportsimportantvulnerabilities PasswordweaknessesGuestaccountnotdisabledAuditingnotconfiguredUnnecessaryservicesinstalledIISvulnerabilitiesIEzonesettingsAutomaticUpdatesconfigurationInternetConnectionFirewallconfiguration MBSA ScanOptions MBSAhasthreescanoptionsMBSAgraphicaluserinterface GUI MBSAstandardcommand lineinterface mbsacli exe HFNetChkscan mbsacli exe hf BusinessCaseForPatchManagement Whendeterminingthepotentialfinancialimpactofpoorpatchmanagement consider DowntimeRemediationtimeQuestionabledataintegrityLostcredibilityNegativepublicrelationsLegaldefensesStolenintellectualproperty WecommendMicrosoftforprovidingenhancedsecurityguidancetoitscustomersaswellasforsolicitinguserinputaspartoftheprocessofproducingthatguidance ClintKreitnerPresident CEO NISTreviewedandprovidedtechnicalcomments advice thatwasincorporatedinthisguidance TimothyGranceManagerSystemsandNetworkSecurityGroup Comments YouNeedTo ISADelivers RelationalReportingMultiplefacttablesFullrichnessthedimensions attributesTransactionlevelaccessStar snowflake 3NF Complexrelationships Multi grains many to many roleplaying indirect RecursiveselfjoinsSlowlychangingdimensions TheUnifiedDimensionalModel TheBestOfRelationalAndOLAP OLAPCubesMultidimensionalnavigationHierarchicalpresentationFriendlyentitynamesPowerfulMDXcalculationsCentralKPIframework Actions LanguagetranslationsMultipleperspectivesPartitionsAggregationsDistributedsources VisualStudioTeamSystem ChangeManagement WorkItemTracking Reporting ProjectSite VisualStudioTeamFoundation IntegrationServices ProjectManagement ProcessandArchitectureGuidance VisualStudioIndustryPartners DynamicCodeAnalyzer VisualStudioTeamArchitect StaticCodeAnalyzer CodeProfiler UnitTesting CodeCoverage VisioandUMLModeling TeamFoundationClient VSPro ClassModeling LoadTesting ManualTesting TestCaseManagement ApplicationModeling LogicalInfra Modeling DeploymentModeling VisualStudioTeamDeveloper VisualStudioTeamTest ApplicationModeling LogicalInfra Modeling DeploymentModeling ClassModeling SQLServerCatalog ReportServer XMLWebServiceInterface ReportProcessing Delivery DeliveryTargets E mail SharePoint Custom Rendering OutputFormats HTML Excel PDF Custom DataProcessing DataSources SQL OLEDB XML A ODBC Oracle Custom Security SecurityServices NT Passport Custom Office CustomApplication Browser SQLServer2000ReportingServicesArchitecture Internet RASClient RRASServer IASServer Quarantine RQC exeandRQS exeareintheWindowsServer2003ResourceKit QuarantineArchitecture WhatisVSTeamFoundation SourceCodeControl WorkItemTracking BuildAutomation ProjectSite Reporting MicrosoftBIProductSuite AnalysisServicesOLAP DataMining DataTransformationServices SQLServerRelationalEngine ReportingServices ManagementTools DevToolsVisualStudio Net ExcelOWCVisioMapPointDataAnalyzer SharePointPortalServerProjectServer WindowsServer MBSBIApplications CurrentArchitecture TCP IP RTCClientAPI UserApp ServerArchitecture Winsock Storage AD Server ApplicationInteraction Application1CRM Application2Billing Application3Logging Request ModifiedRequest TITLE Available Today Microsoft Windows SecurityResourceKit AssessingNetworkSecurity June23 2004 EAParchitecture TLS GSS APIKerberos PEAP IKE MD5 EAP PPP 802 3 802 5 802 11 Anything methodlayer EAPlayer medialayer MS CHAPv2 TLS SecurID PartnerSolutionsOfferings VALUEProposition GetmorebusinessvaluefromyourinvestmentinOffice FinanceSarbanes OxleyBusinessScorecardExcelAdd inforSQLServerAnalysisServices OperationsSixSigma HRRecruiting SalesProposals SolutionAccelerators MicrosoftProducts OfficeSolutionAccelerators VALUEProposition GetmorebusinessvaluefromyourinvestmentinOffice YourPeople EPMInvolves YourBusinessProcesses YourOrganization YourSoftwareTechnology Tools Anorchestrationofyourpeople processes organizationwithtechnology YourBusinessProcesses Governance Prioritization Budgeting HumanResources etc Initiatives ImplementMicrosoftOfficeProject2003fortheEnterprise Decisions CorporateGoalsandObjectives Executives YourOrganization StrategicInitiatives DevelopmentProjects OperationalImprovements OnAverage45 50 ofallProjectsarelinkedtoStrategicObjectives RepresentativeRisksAndTactics TacticalSolutions EnterpriseRisks EmbodyTrustworthyComputing SecureEnvironmentalRemediation UnpatchedDevices NetworkSegmentationThroughIPSec UnmanagedDevices SecureRemoteUser RemoteandMobileUsers Two FactorforRemoteAccessandAdministrators Single FactorAuthentication ManagedSourceInitiatives FocusControlsAcrossKeyAssets RemoteAccessSecurity Threat Requirement Solution Malicioususers Twofactorauthentication SmartCardsforRAS Malicioussoftware Enforceremotesystemsecurityconfiguration ConnectionManager customscriptsandtoolsprovidedintheWindows2003resourcekit CorporateSecurityGroupOrganization CorporateSecurityGroup Threat RiskAnalysis andPolicy AssessmentandCompliance Monitoring IntrusionDetection andIncidentResponse SharedServicesOperations ThreatandRiskAnalysis PolicyDevelopment ProductEvaluation DesignReview StructureStandards SecurityManagement SecurityAssessment ComplianceandRemediation MonitoringandIntrusionDetection RapidResponseandResolution Forensics ITInvestigations PhysicalandRemoteAccess CertificateAdministration SecurityTools InitiativeManagement ServerFunctions OperationalInfrastructure ServerWorkloadsFocus Application WebServerUnixintegrationservices Workloads Solutions ApplicationPlatform InformationWorkerInfrastructure DatabaseHighPerformanceComputing SoftwareDistributionVirtualizationOperationsMgmtTerminalServer EmailCollaboration BranchOfficeMediumBusinessSmallBusiness NetworkingRemoteAccessSecurityIdentityMgmt Storage file portal Print WhatIsMapPointWebService Functionalities APIsMaps Geocoding ReverseGeocoding ProximitySearch FindAddressetc DevelopmentToolsVisualStudio Net Linux VisualBasic Mac Java C XMLWebService PointsofInterestDatabaseofmorethan200 000and16millionbusinesslistings CartographicdataExtensivegeographiccoveragein19countriesinEuropeandNorthAmerica NoUIconstraints deviceindependent Integrationintoabroadrangeofdifferentapplicationsanddevices 2004 2005 WindowsSmallBusinessServer2003SP1WindowsServer2003for64 BitExtendedSystemsWindowsServer2003ServicePack1 SP1 WindowsXPTabletEdition2005WindowsXPMediaCenterEdition2005WindowsXPServicePack2 SP2 VirtualServer2005AdditionalFeaturePacks e g WindowsUpdateServices WindowsServer Codename Longhorn Beta1WindowsClient Codename Longhorn Beta1WindowsServer2003Update Codename R2 ReleaseRoadmap 第二篇表格篇 MicrosoftPatchSeverityRatings SecurityBulletinList http www M PatchingTimeFrames ImprovingThePatchingExperience ChoosingAPatchManagementSolution PatchManagementSolutionForMedium SizedAndLargeOrganizations OtherSessionsOfInterest TheImportanceOfProactivePatchManagement DREAD MicroIssuesare88 Simpletofix Create Noise Fiveissuesrepresent88 ofallupgradeissues AnalysisServiceandDTSMigrationWizardsNonewMDACbitsReducedSQLDatabaseservicesdowntime Upgrade ExampleGoals ExampleScope Whattoplanfor PatchManagementSolutionForSmallAndMedium sizedOrganizations ElementsofYourFinalReport What sNewInSetup DefaultExemptRulesInIPSec Storedintheregistryvalue HKLM SYSTEM CurrentControlSet Services IPSEC NoDefaultExempt PerformanceEnhancedArchitecture OptimizedforreallifeusagescenariosImprovementssinceISAServer2000Kernel modedatapumpUser modeoptimizationsUpto 150 2 5Xfaster forfirewall SecureNAT trafficUpto 250 3 5Xfaster forWeb transparent proxytraffic1 000 000 concurrentconnectionsScaleupwithadditionalCPUs Rawthroughputperformance How DesignimprovementsIPStackimprovementsHardwareimprovements rawthru putmeasuredusingHTTP NATbenchmark ITPolicyCompleteness ITAuditScoreCardExample UpgradingAndMigratingSharePointproductsandtechnologies OtherSessions WindowsServerFamily Dedicated 第三篇圖例篇 Corpnet Internet RADIUSAuthentication FederationthroughRADIUSproxiesCanbeusedforcentralizedauthenticationservicesDomainmembershipnotrequiredGreatforDMZplacement RADIUSServer IAS Back endServer WebClient Browser HTTPclient ISAServer2000 Old NetworkingModel Fixedzones IN LAT OUT DMZ InternetPacketfilteronlyonexternalinterfacesSingleoutboundpolicyNATalwaysStaticfilteringfromDMZtoInternet InternalNetwork Internet DMZ1 ISA2000 ISAServer2004NetworkingModel AnynumberofnetworksVPNasnetworkLocalhostasnetworkAssignedrelationships NAT Route Per NetworkpolicyPacketfilteringonallinterfacesSupportforDoDAnytopology anypolicy ISA2004 RuleStructure PolicyMapping BasicISA2000rulesProtocolrulesSiteandContentrulesStaticpacketfiltersPublishingrulesWebpublishingrulesSelectedfilteringconfigurationOtherISA2000rulesAddresstranslationrulesWebroutingrules Firewallpolicy Configurationpolicy actionontrafficfromuserfromsourcetodestinationwithconditions AllowDeny SourcenetworkSourceIPOriginatinguser DestinationnetworkDestinationIPDestinationsite ProtocolIPPort Type PublishedserverPublishedwebsiteScheduleFilteringproperties AnyuserAuthenticatedusersSpecificUser Group PolicyEngine NDI
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 探索商業(yè)美術(shù)設(shè)計(jì)師考試新理念試題及答案
- 廣西毛概期末試題及答案
- 民法基礎(chǔ)考試試題及答案
- 2024年廣告設(shè)計(jì)師用戶體驗(yàn)設(shè)計(jì)能力試題及答案
- 梅州二模試題及答案政治
- 國際美術(shù)設(shè)計(jì)師社交技能與影響力試題及答案
- 系統(tǒng)化設(shè)計(jì)思維的培養(yǎng)試題及答案
- 煤礦電梯考試題及答案
- 奇葩國考試題及答案
- 廣告設(shè)計(jì)師考試設(shè)計(jì)實(shí)踐題型及答案
- 《運(yùn)動(dòng)健康知識(shí)講座》課件
- 熱射病的基礎(chǔ)護(hù)理
- 線性代數(shù)知到智慧樹章節(jié)測試課后答案2024年秋南京理工大學(xué)
- 電力增容項(xiàng)目施工組織設(shè)計(jì)
- 職業(yè)衛(wèi)生技術(shù)服務(wù)機(jī)構(gòu)檢測人員考試真題題庫
- DB35T 2212-2024消防遠(yuǎn)程監(jiān)控系統(tǒng)技術(shù)要求
- 超市保證食品安全的規(guī)章制度
- 微風(fēng)發(fā)電審批流程詳解
- 【課件】人居與環(huán)境-詩意的棲居+課件高中美術(shù)人美版(2019)+必修+美術(shù)鑒賞
- 抖音本地生活商家直播培訓(xùn)
- 6.3基層群眾自治制度 說課課件高中政治統(tǒng)編版必修三政治與法治
評(píng)論
0/150
提交評(píng)論