經(jīng)典素材庫合集(超級(jí)絕版)-區(qū)塊、表格篇_第1頁
經(jīng)典素材庫合集(超級(jí)絕版)-區(qū)塊、表格篇_第2頁
經(jīng)典素材庫合集(超級(jí)絕版)-區(qū)塊、表格篇_第3頁
經(jīng)典素材庫合集(超級(jí)絕版)-區(qū)塊、表格篇_第4頁
經(jīng)典素材庫合集(超級(jí)絕版)-區(qū)塊、表格篇_第5頁
已閱讀5頁,還剩78頁未讀, 繼續(xù)免費(fèi)閱讀

下載本文檔

版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)

文檔簡介

第一篇區(qū)塊篇IntegratedphoneandPDAPrimarilydataviewingInteroperabilitywithOutlookandExchange.NETCompactFrameworkASP.NETmobilecontrolsMobileDeviceSolutionsComplexdocumentauthoring,editingandreadingKeyboardcentricatthedeskKeyboardandmouseinputmethodsFull.NETframeworkavailableCentrinoSolutionsWindowsMobileWindowsXPComplexdocumentauthoring,editingandactivereadingNotetakingandinkannotatingKeyboardcentricatthedesk,penandkeyboardawayfromthedeskKeyboard,mousepluspen,ink,andspeechinputmethodsFull.NETframeworkpreinstalledPen,ink,handwritingandspeechrecognitionAPI’sCentrinoSolutionsViewandsomedataentryIntegratedPDAwithphoneInteroperabilitywithOffice,ExchangeandSQLServer.NETCompactFrameworkASP.NETmobilecontrolsIntelXscaleSolutionsWindows?CEOne-waynetworkInformationconsumptionSmartPersonalObjectsSmartphonePocketPCandPocketPCPhoneNotebookPCTabletPCNetworkDefenseHealthcheckupITchecks“health〞ofclientNetworkAccessControlClientswhopassgetnetworkaccessClientswhodonotpassarefixedorblocked(aka“quarantined〞)HealthmaintenanceQuarantinedclientscanbegivenaccesstoresourcestogethealthyFromHome

(VPN,Dialup)ReturningLaptopsConsultants

GuestsUnhealthy

DesktopsMicrosoftBusinessSolutionsERPPositioningProjectManagementandAccountingERPPrimarilyinUSandLatinAmericaMid-marketERPTypicallycustomizedforuniquebusinessprocessesGlobalERPMultinationalsAdvancedmanufacturersMid-marketERPRichout-of-the-boxfunctionalityGuidingPrinciplesProductiveIntegratedExtensibleCapableShortlearningcurveMinimaladministrativeoverheadToolsintegratedtightlyAutomatescommontasksCustomizableforyourprocessIntegrateswith3rdpartytoolsRemotelyaccessibleRobust,secure,scalableStagingArchitectureDataentryTestApplicationCenterCommerceWebCommerceCommerceDataCommerceWebCommerceCommerceDataApplicationCenterApplicationCenterDataACSClusterACSClusterClustercontrollerClustercontrollerDataLiveCommunicationsClientRoadmapLC1.2ClientPlatformMultipartyIMP2PVoice

andVideoMPOPGroupsRoamingSIPsupportGPOpolicymanagementLC1.5ClientPlatformRollupofQFEsMPOPAdditionsFederation/ArchivingNotificationHAAdditionsLC2.0ClientPlatformNextgenerationofRTCexperiencesMorecoming!20032H04LonghornEnterpriseDeploymentUpdateInternetFirewallFirewallFirewallRuntimeServersCorporateLAN–InternalServersCrawl/SearchLoadBalancedWebInfrastructureServersDevelopmentServersTestServersBusinessDataServersBusinessUsersDatabaseandStagingServersStagingServersDatabaseServersOfflineServersIndicatesStagedDataFlowCommunicateandcollaborateinamoresecuremanner

withoutsacrificinginformationworkerproductivityWindowsXPSP2

Blockvirusormaliciouscodeatthe“pointofentry〞

AtRiskTheSoftUnderbellySecurityIssuesToday1Source:ForresterResearch2Source:InformationWeek,26November20013Source:Netcraftsummary4Source:CERT,20035Source:CSI/FBIComputerCrimeandSecuritySurvey6Source:ComputerSecurityInstitute(CSI)ComputerCrimeandSecuritySurvey20027Source:CERT,20028Source:GartnerGroup14BdevicesontheInternetby2021135Mremoteusersby2005265%increaseindynamicWebsites3From2000to2002reportedincidentsrosefrom21,756to82,0944Nearly80percentof445respondentssurveyedsaidtheInternethasbecomeafrequentpointofattack,upfrom57percentjustfouryearsago590%detectedsecuritybreaches685%detectedcomputerviruses695%ofallbreachesavoidablewithanalternativeconfiguration7Approximately70percentofallWebattacksoccurattheapplicationlayer8ApplicationLayerAttacksIdentityTheftWebSiteDefacementUnauthorizedAccessModificationofData,LogsandRecordsTheftofProprietaryInformationServiceDisruptionImplicationsCompliance:SarbanesOxleyGrammLeachBlilelyUSPatriotActHIPAA ThePrivacyAct(CA)Basel2(EU)DataProtectionAct(EU)LitigationFileSharingPiracyHRIssuesShareholderSuitsCustomerImpactTypesOfSRPRulesPathRuleComparespathoffilebeingruntoanallowedpathlistUsewhenyouhaveafolderwithmanyfilesforthesameapplicationEssentialinwhenSRPsarestrictHashRuleComparestheMD5orSHA1hashofafiletotheoneattemptedtoberunUsewhenyouwanttoallow/prohibitacertainversionofafilefrombeingrunCertificateRuleChecksfordigitalsignatureonapplication(i.e.Authenticode)Usewhenyouwanttorestrictbothwin32applicationsandActiveXcontentInternetZoneRuleControlshowInternetZonescanbeaccessedUsewheninhighsecurityenvironmentstocontrolaccesstowebapplicationsSQLServer2005ThemesSupportability&QualityEnterpriseEnhancementsUnified&FlexibleAdministrationPatchSolutionsPrevention,Readiness,RecoveryEaseofusePatchInstallsPatchinintegratedstepIntegratedDatabaseServicesandBusinessIntelligenceFlexibleinstallmanagementAddvaluetoone-stepFailoverClusteringExpandedscriptingsupportTraditionalFirewallsWideopentoadvancedattacksPerformanceversus

securitytradeoffLimitedcapacityforgrowthHardtomanageCodeRed,NimdaSSL-basedattacksSecurityiscomplexITisalreadyoverloadedBandwidthtooexpensiveToomanymovingpartsNoteasilyupgradeableDon’tscalewithbusinessChoosingtheRightTypeofAssessment

VulnerabilityScanningFocusesonknownweaknessesOfthethree,requirestheleastexpertiseGenerallyeasytoautomatePenetrationTestingFocusesonknownandunknownweaknessesRequiresadvancedtechnicalexpertiseCarriestremendouslegalburdenincertaincountries/organizationsITSecurityAuditsFocusesonsecuritypoliciesandproceduresOfthethree,requiresthemostexpertiseWhendonerightisthemosteffectivetypeofassessmentPerimeterSecurityEvolutionWideopentoadvancedattacksApplication-levelprotectionPerformanceversus

securitytradeoffSecurityandperformanceLimitedcapacityforgrowthExtensibilityandscalabilityHardtomanageEasiertouseThe

advancedapplicationlayerfirewall,VPNandWebcache

solutionthatenablescustomerstomaximizeITinvestmentsbyimprovingnetworksecurityandperformanceAdvancedprotectionApplicationlayersecuritydesignedtoprotectMicrosoftapplicationsFast,secureaccessEmpowersyoutoconnectuserstorelevantinformationonyour

networkinacostefficientmannerEaseofuseEfficientlydeploy,manage,andenablenewusagescenariosIntroducing:ISAServer2004Fast,secureaccessEmpowersyoutoconnectuserstorelevantinfo.onyournetworkISAServer2004NewFeatures

ContinuedcommitmenttointegrationEnhancedarchitecture

HighspeeddatatransportUtilizeslatestWindowsandPChardwareSSLbridgingunloadsdownstreamserversWebcache

UpdatedpolicyrulesServecontentlocallyPre-fetchcontentduringlowactivityperiodsInternetaccesscontrol

User-andgroup-basedWebusagepolicyExtensiblebythirdpartiesComprehensiveauthentication

NewsupportforRADIUSandRSASecurIDUser-&group-basedaccesspolicyThirdpartyextensibilitySystemServiceAccountsLocalServiceandNetworkServiceNopasswordtomanageRunswithonlyslightlymorepermissionsthanAuthenticatedUserLocalServicecannotauthenticateacrossthenetwork,NetworkServiceauthenticatesasthecomputeraccountLocalSystemNopasswordtomanageBypassessecuritychecksUserAccountsRunwithlessprivilegethanLocalSystemStorespasswordasanLSAsecretCanbecomplextoconfigureWhat’sNewWithIPSec?ManagementIPSecurityMonitorCommand-linemanagementwithNetshLogicaladdressesforlocalIPconfigurationSecurityStrongercryptographicmasterkey(Diffie-Hellman)ComputerstartupsecurityPersistentpolicyforenhancedsecurityAbilitytoexcludethenameoftheCAfromcertificaterequestsBetterdefaultexemptionhandlingInteroperabilityIPSecfunctionalityovernetworkaddresstranslation(NAT)ImprovedIPSecintegrationwithNetworkLoadBalancingISAServer2004NewFeatures

NewmanagementtoolsanduserinterfaceMulti-networkarchitectureUnlimitednetworkdefinitionsandtypesFirewallpolicyappliedtoalltrafficPernetworkroutingrelationshipsNetworktemplatesandwizardsWizardautomatesnwkroutingrelationshipsSupports5commonnetworktopologiesEasilycustomizedforsophisticatedscenariosVisualpolicyeditorUnifiedfirewall/VPNpolicyw/onerule-baseDrag/dropeditingw/scenario-drivenwizardsXML-basedconfigurationimport-exportEnhancedtrouble-shootingAllnewmonitoringdashboardReal-timelogviewerContentsensitivetaskpanesEaseofUseEfficientlydeploy,manage,andenablenewusagescenariosHowToUseWindowsUpdateToconfigureAutomaticUpdates:SelectKeepmycomputeruptodateOpentheSystemapplicationinControlPanel1OntheAutomaticUpdatestab,selectthe

optionyouwant32OfficeUpdateBenefitsLimitationSinglelocationforofficepatchesandupdatesEasytouseCanbeconfiguredtoupdateconsumeror

enterprisesystemsDoesnotsupportAutomaticUpdates;updatingmustbeinitiatedmanuallyOfficeUpdateWebsite:

HowToUseOfficeUpdate1ClickCheckforUpdates2InstalltheOfficeUpdateInstallationEngine

(ifnotalreadyinstalled)3Selecttheupdatesyouwanttoinstall4ClickStartInstallation5HowToUseSUSOntheSUSserverConfiguretheSUSserverat

://<servername>/SUSAdminOneachSUSclientConfigureAutomaticUpdatesontheclienttousetheSUSserverUseGroupPolicy,manuallyconfigureeachclient,or

usescriptsSettheSUSserversynchronizationscheduleReview,test,andapproveupdates123HowToUseMBSADownloadandinstallMBSA(onceonly)1LaunchMBSA2Selectthecomputer(s)toscan3Selectrelevantoptions4ClickStartscan5ViewtheSecurityReport6SoftwareUpdateServiceDeploymentBestPractices(1)RevieweachsecuritypatchDownloadandinstallthepatchTesteachsecuritypatchbeforedeploymentConfigureatestlabUseatestSUSserverConsiderusingVirtualPCsinthetestlabUseastandardacceptancetestingprocedureSoftwareUpdateServiceDeploymentBestPractices(2)CompletethedeploymentPilotthedeploymentConfigureachildSUSservertoapproveupdatesConfigureaGPOsothatthepatchisdownloadedfromthepilotSUSserveronlybyspecifiedworkstationsIfthepilotfails,removeapprovalfromtheSUSserverandmanuallyuninstallthepatchHowToUseSMSToDeployPatchesOpentheSMSAdministratorConsole1Right-clickAllWindowsXPComputers,andthenselectAllTasks>DistributeSoftwareUpdates3Usethewizardtocreateanewpackageandprogram4Browsetothepatchtobedeployed5Configureoptionsforhowandwhenthepatchwillbedeployedtoclients6ExpandtheSiteDatabasenode2SMS–MBSAIntegrationMBSAintegrationincludedwithSMS2003andthe

SUSFeaturePackforSMS2.0ScansSMSclientsformissingsecurityupdatesusingmbsacli.exe/hfSMSdirectsclienttorunlocalMBSAscan1SMSserverparsesdatatodeterminewhichcomputersneedwhichsecurityupdates3Administratorpushesmissingupdatesonlytoclientsthatrequirethem4Clientperformsscan,returnsdatatoSMSserver2MBSABenefitsScanssystemsforMissingsecuritypatchesPotentialconfigurationissuesWorkswithabroadrangeof

MicrosoftsoftwareAllowsanadministratortocentrallyscanmultiplecomputerssimultaneously MBSAisafreetool,andcanbe

downloadedfrom

MBSAConsiderationsMBSAreportsimportantvulnerabilitiesPasswordweaknessesGuestaccountnotdisabledAuditingnotconfiguredUnnecessaryservicesinstalledIISvulnerabilitiesIEzonesettingsAutomaticUpdatesconfigurationInternetConnectionFirewallconfigurationMBSA–ScanOptionsMBSAhasthreescanoptionsMBSAgraphicaluserinterface(GUI)MBSAstandardcommand-line

interface(mbsacli.exe)HFNetChkscan(mbsacli.exe/hf)BusinessCaseFor

PatchManagementWhendeterminingthepotentialfinancialimpactofpoorpatchmanagement,considerDowntimeRemediationtimeQuestionabledataintegrityLostcredibilityNegativepublicrelationsLegaldefensesStolenintellectualproperty“WecommendMicrosoftforprovidingenhancedsecurityguidancetoitscustomersaswellasforsolicitinguserinputaspartoftheprocessofproducingthatguidance“ClintKreitnerPresident/CEO“NISTreviewedandprovidedtechnicalcomments&advice,thatwasincorporatedinthisguidance〞TimothyGranceManagerSystemsandNetwork

SecurityGroupCommentsSecurelymakee-mailavailabletooutsideemployeesExchangepublishingYouNeedTo…SecurelymakeinternalapplicationsavailableontheInternetWebandServerPublishingEnablepartnerstoaccessrelevantinformationonmynetworkIntegratedS2SVPNandFWSecureandflexibleremoteaccess,whileprotectingmycorporatenetworkIntegratedRRASVPNandFWSecurelyconnectmybranchofficestothecorporateofficeIntegratedFW,VPN,CacheControlInternetAccessandprotectmyclientsfrommaliciousInternettrafficFW,WebProxyEnsurefastaccesstothemostfrequentlyusedwebcontentCachingISADeliversRelationalReportingMultiplefacttablesFullrichnessthedimensions’

attributesTransactionlevelaccessStar,snowflake,3NF…Complexrelationships:Multi-grains,many-to-many,roleplaying,indirect…RecursiveselfjoinsSlowlychangingdimensionsTheUnifiedDimensionalModel–

TheBestOfRelationalAndOLAPOLAPCubesMultidimensionalnavigationHierarchicalpresentationFriendlyentitynamesPowerfulMDXcalculationsCentralKPIframework“Actions”LanguagetranslationsMultipleperspectivesPartitionsAggregationsDistributedsourcesVisualStudioTeamSystemChangeManagementWorkItemTrackingReportingProjectSiteVisualStudio

TeamFoundationIntegrationServicesProjectManagementProcessandArchitectureGuidanceVisualStudioIndustryPartnersDynamicCodeAnalyzerVisualStudio

TeamArchitectStaticCodeAnalyzerCodeProfilerUnitTestingCodeCoverageVisioandUMLModelingTeamFoundationClientVSProClassModelingLoadTestingManualTestingTestCaseManagementApplicationModelingLogicalInfra.ModelingDeploymentModelingVisualStudio

TeamDeveloperVisualStudio

TeamTestApplicationModelingLogicalInfra.ModelingDeploymentModelingClassModelingSQLServerCatalogReportServerXMLWebServiceInterfaceReportProcessingDeliveryDeliveryTargets(E-mail,SharePoint,Custom)RenderingOutputFormats(HTML,Excel,PDF,Custom)DataProcessingDataSources(SQL,OLEDB,XML/A,ODBC,Oracle,Custom)SecuritySecurityServices(NT,Passport,Custom)OfficeCustomApplicationBrowserSQLServer2000ReportingServices

ArchitectureCMProfileRunscustomizable

postconnectscriptScriptrunsRQCnotifier

with“resultsstring”ListenerRQSreceivesNotifier

“resultsstring”Comparesresultsto

possibleresultsRemovestime-outif

responsereceivedbut

clientoutofdateRemovesquarantinefilter

ifclientuptodateQuarantineVSAsTimerlimitstime

windowtoreceivenotifybeforeautodisconnectQ-filtersetstemporaryroutefiltertoquarantineaccessInternetRASClientRRASServerIASServerQuarantineRQC.exeandRQS.exeareintheWindowsServer2003ResourceKitQuarantineArchitectureWhatisVSTeamFoundation?SourceCodeControlWorkItemTrackingBuildAutomationProjectSiteReportingMicrosoftBIProductSuiteAnalysisServicesOLAP&DataMiningDataTransformationServicesSQLServerRelationalEngineReportingServicesManagementToolsDevToolsVisualStudio.NetExcelOWCVisioMapPointDataAnalyzerSharePointPortalServerProjectServerWindowsServerMBSBIApplicationsCurrentArchitectureTCP/IPRTCClientAPIUserAppRTPSIPPINTT.120ServerArchitectureApplicationManagedAPIsApplicationManagedAPIsWinsockStorageADDispatcherDataStoreInterfacesSPLScriptEngineRegistrar/PresenceSIPProxyServerApplicationInteractionApplication

1CRMApplication

2BillingApplication

3LoggingRequestModified

RequestTITLEAvailableTodayMicrosoft?Windows?SecurityResourceKitAssessingNetworkSecurityJune23,2004EAParchitectureTLSGSS_APIKerberosPEAPIKEMD5EAPPPP802.3802.5802.11Anything…methodlayerEAPlayermedialayerMS-CHAPv2TLSSecurIDPartnerSolutionsOfferingsVALUEProposition:

GetmorebusinessvaluefromyourinvestmentinOfficeFinanceSarbanes-OxleyBusinessScorecardExcelAdd-inforSQLServerAnalysisServicesOperationsSixSigmaHRRecruitingSalesProposalsSolutionAcceleratorsMicrosoftProductsOfficeSolutionAcceleratorsVALUEProposition:

GetmorebusinessvaluefromyourinvestmentinOfficeYourPeopleEPMInvolves….YourBusinessProcesses

YourOrganizationYourSoftwareTechnology&ToolsEnterpriseProjectManagementAnorchestrationofyourpeople,processes,organizationwithtechnologyYourBusinessProcesses…GovernancePrioritizationBudgetingHuman

Resources…

etc…InitiativesImplementMicrosoftOfficeProject2003fortheEnterpriseDecisions-CorporateGoalsandObjectivesExecutivesFinanceSalesandMarketingR&DIT/ISYourOrganization…StrategicInitiativesHRDevelopmentProjectsOperationalImprovementsOnAverage45-50%ofallProjectsarelinkedtoStrategicObjectives.RepresentativeRisksAndTacticsTacticalSolutionsEnterpriseRisksEmbodyTrustworthyComputingSecureEnvironmentalRemediationUnpatchedDevicesNetworkSegmentationThroughIPSecUnmanagedDevicesSecureRemoteUserRemoteandMobileUsersTwo-FactorforRemoteAccessandAdministratorsSingle-FactorAuthenticationManagedSourceInitiativesFocusControlsAcrossKeyAssetsRemoteAccessSecurity

ThreatRequirementSolutionMalicious

usersTwofactorauthenticationSmartCards

forRASMalicious

softwareEnforceremotesystemsecurityconfigurationConnectionManager,customscriptsandtoolsprovidedintheWindows2003resourcekitCorporateSecurityGroupOrganizationCorporateSecurityGroupThreat,Risk

Analysis,andPolicyAssessmentand

ComplianceMonitoring,IntrusionDetection,andIncidentResponseSharedServices

OperationsThreatandRisk

AnalysisPolicy

DevelopmentProduct

EvaluationDesign

ReviewStructure

StandardsSecurity

ManagementSecurity

AssessmentComplianceand

RemediationMonitoringand

IntrusionDetectionRapidResponse

andResolution

ForensicsIT

InvestigationsPhysicaland

RemoteAccessCertificate

AdministrationSecurity

ToolsInitiative

ManagementServerFunctionsOperationalInfrastructureServerWorkloadsFocusApplication/WebServerUnixintegrationservicesWorkloadsSolutionsApplicationPlatformInformationWorkerInfrastructureDatabaseHighPerformanceComputingSoftwareDistributionVirtualizationOperationsMgmtTerminalServerEmailCollaborationBranchOfficeMediumBusinessSmallBusinessNetworkingRemoteAccessSecurityIdentityMgmtStorage(file,portal)PrintWhatIsMapPointWebService?Functionalities/APIsMaps,Geocoding,ReverseGeocoding,ProximitySearch,FindAddressetc.DevelopmentToolsVisualStudio.Net,Linux,VisualBasic,Mac,Java,C#…XMLWebService

PointsofInterestDatabaseofmorethan200,000and16millionbusinesslistingsCartographicdataExtensivegeographiccoveragein19countriesinEuropeandNorthAmerica.NoUIconstraints;deviceindependent.Integration

intoabroadrangeof

differentapplications

anddevices.20042005WindowsSmallBusinessServer2003SP1WindowsServer2003for64-BitExtendedSystemsWindowsServer2003ServicePack1(SP1)WindowsXPTabletEdition2005WindowsXPMediaCenterEdition2005WindowsXPServicePack2(SP2)VirtualServer2005AdditionalFeaturePacks(e.g.WindowsUpdateServices)WindowsServer:Codename“Longhorn〞Beta1WindowsClient:Codename“Longhorn〞Beta1WindowsServer2003Update:Codename“R2〞ReleaseRoadmap第二篇表格篇MicrosoftPatchSeverityRatingsSecurityBulletinList:

RatingDefinitionCriticalExploitationcouldallowthepropagationofanInternetwormImportantExploitationcouldresultincompromiseofuserdataortheavailabilityofprocessingresourcesModerateExploitationisserious,butismitigatedtoasignificantdegreebydefaultconfiguration,auditing,needforuseraction,ordifficultyofexploitationLowExploitationisextremelydifficultorimpactisminimalPatchingTimeFramesSeverityratingRecommendedpatchingtimeframeRecommended

maximumpatchingtimeframeCriticalWithin24hoursWithintwoweeksImportantWithinonemonthWithintwomonthsModerateDependingonexpectedavailability,waitfornextservicepackorpatchrollupthatincludesthepatch,ordeploythepatchwithinfourmonthsDeploythepatchwithinsixmonthsLowDependingonexpectedavailability,waitfornextservicepackorpatchrollupthatincludesthepatch,ordeploythepatchwithinoneyearDeploythepatchwithinoneyear,orchoosenottodeployatallImprovingThePatchingExperienceYourneedMicrosoft’sresponseReducepatchfrequencyReducedfrequencyofnon-emergencypatchreleasesfromonceperweektooncepermonthReducepatchingcomplexityReducednumberofpatchinstallertechnologiesReduceriskofpatchdeploymentImprovedpatchqualityandintroduced

patchrollbackcapabilityReducepatchsizeDeveloped“deltapatching”technologyto

reducepatchsizeReducedowntimeReducedpatch-relatedrebootsImprovetoolconsistencyDevelopingconsistenttoolsImprovetoolcapabilitiesDevelopingmorecapabletoolsChoosingAPatch

ManagementSolutionCustomertypeScenarioSolutionConsumerAllscenariosWindowsUpdateSmallorganizationHasnoWindowsserversWindowsUpdateHasonetothreeWindows2000

ornewerserversandoneITadministratorMBSAandSUSMedium-sizedorlargeenterpriseWantsapatchmanagementsolutionwithbasiclevelofcontrolthatupdatesWindows2000andnewerversionsofWindowsMBSAandSUSWantsasingleflexiblepatchmanagementsolutionwithextendedlevelofcontroltopatch,update,anddistributeallsoftwareSMSPatchManagementSolutionForMedium-SizedAndLargeOrganizationsCapabilitySUS1.0SMS2003

Supported

Platformsfor

Content

Windows2000

WindowsXP

WindowsServer2003

WindowsNT4.0

Windows98

Windows2000WindowsXP

WindowsServer2003

Supported

ContentTypes

Securityandsecurity

rolluppatches,critical

updates,andservice

packsfortheabove

operatingsystems

Allpatches,servicepacks,and

updatesfortheaboveoperating

systems;supportspatch,

update,andapplication

installationsforMicrosoftand

otherapplications

Patch

Distribution

Control

Basic

AdvancedOtherSessionsOfInterestWIN280MicrosoftVirtualServer2005:TechnicalOverviewMon,May24

1:30-2:45PMRoom20AWINC28Q&AWiththeVirtualServer

TeamTues,May25

1:30–2:45PMCabana13WIN383UsingMicrosoftVirtualServer2005toInstalla

2-NodeClusterofVirtual

MachinesTues,May25

3:15-4:30PMRoom31ABCWIN381AdvancedConfigurationsScenariosforVirtualServer2005Tues,May25

5:00-6:15PMRoom31ABCWINC10ConsolidatingNT4ApplicationsUsingWindowsVirtualServer2005Wed,May26

10:15-11:30AMCabana12WINC13CreatingaVirtualTestLabwithMicrosoftVirtualServer

2005Wed,May26

5:30-6:45PMCabana12TheImportanceOfProactivePatchManagementAttackPatchreleasedateAttackdateNumberofdayspatchwasavailablebeforetheattackTrojan.KahtMar17,2003May,5200349SQLSlammerJul24,2002Jan24,2003184Klez-EMar29,2001Jan17,2002294NimdaOct17,2000Sept18,2001336CodeRedJun18,2001Jul16,200128DREADHigh(3)Medium(2)Low(1)DamagepotentialAttackercanretrieveextremelysensitivedataandcorruptordestroydataAttackercanretrievesensitivedatabutdolittleelseAttackercanonlyretrievedatathathaslittleornopotentialforharmReproduc-abilityWorkseverytime;doesnotrequireatimingwindowTiming-dependent;worksonlywithinatimewindowRarelyworksExploitabilityBartSimpsoncoulddoitAttackermustbesomewhatknowledgeableandskilledAttackermustbeVERYknowledgeableandskilledAffectedusersMostorallusersSomeusersFewifanyusersDiscoverabiltyAttackercaneasilydiscoverthevulnerabilityAttackermightdiscoverthevulnerabilityAttackerwillhavetodigtodiscoverthevulnerabilityMicroIssuesare88%Simpletofix.Create“Noise〞Fiveissuesrepresent88%ofallupgradeissuesDefaultproperties52%Property/methodnotupgraded13%Property/methoddifferentbehavior12%ModulemethodsofCOMobjects7%Null/IsNull4%AnalysisServiceandDTSMigrationWizardsNonewMDACbitsReducedSQLDatabaseservicesdowntimeUpgradeEditionsUpgradeLanguagePlatformSQL2005Beta2DeveloperEditionSQL2000Enterprise,Standard,Developer,&PersonalEditionsSP3orhigherJPNIntelX86IntelIA64ENUIntelAMD64ExampleGoalsProjectGoalInthevulnerabilityscanningproject,allcomputersrunningWindows2000ServerandWindowsServer2003onthesubnets/24and/24willbescannedforthefollowingvulnerabilitiesberemediatedasstated.VulnerabilityRemediationRPCoverDCOMvulnerability(MS03-026)InstallMicrosoftsecuritypatches03-026and03-39.AnonymousSAMenumerationConfigureRestrictAnonymousto:2onWindows2000Server1onWindowsServer2003GuestaccountenabledDisableGuestaccount.Greaterthan10accountsinthelocalAdministratorgroupMinimizethenumberofaccountsontheadministratorsgroup.ExampleScopeStatementComponentsExampleTargetAllserversrunning:*Windows2000Server*WindowsServer2003TargetareaAllserversonthesubnets:/24/24TimelineScanningwilltakeplacefromJune3rdtoJune10thduringnon-criticalbusinesshoursVulnerabilitiestoscanforRPCoverDCOMvulnerability(MS03-026)AnonymousSAMenumerationGuestaccountenabledGreaterthan10accountsinthelocalAdministratorgroupWhattoplanfor…ProjectPhasePlanningElementsPre-assessmentScopeGoalsTimelinesGroundrulesAssessmentChoosingtechnologiesPerformassessmentOrganizeresultsPreparingresultsEstimateriskpresentedbydiscoveredweaknessesCreateaplanforremediationIdentifyvulnerabilitiesthathavenotbeenremediatedDetermineimprovementinnetworksecurityovertimeReportingyourfindingsCreatefinalreportPresentyourfindingsArrangefornextasses

溫馨提示

  • 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。

評(píng)論

0/150

提交評(píng)論