Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Microsoft could finally be cutting down on this security flaw

  • July 27, 2023
Total
0
Shares
0
0
0


Defender for IoT, Microsoft’s IoT-oriented antivirus program, is getting a new feature to cut down on firmware attacks. Called Firmware Analysis, the feature does exactly what the name suggests – analyses firmware in embedded Linux devices for vulnerabilities and known weaknesses. 

The tool, which is currently in Public Preview, can scan the firmware for devices such as routers, looking for known vulnerabilities like hardcoded user accounts, outof-date open-source packages, or the use of the manufacturer’s private cryptographic signing key.

“Firmware analysis takes a binary firmware image that runs on an IoT device and conducts an automated analysis to identify potential security vulnerabilities and weaknesses,” said Microsoft’s Derick Naef. “This analysis provides insights into the software inventory, weaknesses, and certificates of IoT devices without requiring an endpoint agent to be deployed.”

Analyzing firmware

At the moment, the tool offers different tools that analyze IoT device firmware security such as Software Bill of Materials (lists open-source packages used to build the firmware), CVE Analysis (analyses firmware components for publicly known security flaws), Binary Hardening Analysis (lists binaries compiled without security flags), SSL Certificate Analysis (pinpoints expired and revoked TLS/SSL certificates), Public and Private Key Analysis (verifies public and private cryptographic keys in the firmware), and Password Hash Extraction (checks if the password hashes use secure cryptographic algorithms). 

Those interested in giving the new tool a spin should head over to “Firmware analysis (preview) in Defender for IoT and upload the firmware image from their endpoint.

“The Defender for IoT Firmware Analysis feature is automatically available if you currently access Defender for IoT using the Security Admin, Contributor, or Owner role,” Microsoft says. “If you only have the SecurityReader role or want to use Firmware Analysis as a standalone feature, then your Admin must give the FirmwareAnalysisAdmin role.”


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Elon Musk’s Quixotic Quest to Turn X Into an ‘Everything App’

  • July 27, 2023
View Post
Next Article
  • News

Meta Q2 Earnings: Profit Up 16% to $7.8 Billion

  • July 27, 2023
View Post
You May Also Like
View Post
  • News

Samsung’s affordable Galaxy FE series lands – Galaxy S23 FE, Tab S9 FE and Buds FE explained

  • October 3, 2023
View Post
  • News

Quordle today – hints and answers for Wednesday, October 4 (game #618)

  • October 3, 2023
View Post
  • News

Your phone’s about to get loud. Here’s how to manage the National Emergency Alert System Test

  • October 3, 2023
View Post
  • News

Spotify Premium gets a great free audiobooks upgrade – here’s everything you need to know

  • October 3, 2023
View Post
  • News

Spotify Gave Subscribers Music, Podcasts. Next Up: Audiobooks.

  • October 3, 2023
View Post
  • News

AI LLM provider backed by MLPerf cofounder bets barn on mature AMD Instinct MI GPU — but where are the MI300s?

  • October 3, 2023
View Post
  • News

Time to cancel? Netflix rumored to be raising its global prices again soon

  • October 3, 2023
View Post
  • News

Some top ARM GPUs have a potentially worrying security flaw – here’s what you need to know

  • October 3, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.