HomeinetWindows Defender sandboxed: Researchers put it into practice

Windows Defender sandboxed: Researchers put it into practice

Researchers at security firm Trail of Bits (R&D) have managed to sandbox Windows Defender, the default antivirus solution that comes with recent versions of Windows.

Sandboxing is a technical term that describes the act of running an application within a special context. This context prevents an attacker from exploiting the application to reach the underlying operating system.Windows Defender

Current versions of Windows Defender are not sandboxed

It's incredible, but apparently, Windows Defender, a critical part of the Windows operating system, doesn't run in a sandbox environment by default, even though the product – in various forms and names – has been part of the Windows application portfolio for at least 13 years.

The Trail of Bits team has created a framework using Rust that runs Windows applications inside their own AppContainers. The researchers have released this framework under the name AppJailLauncher on GitHub.

“…it allows you to wrap an application’s I/O behind a TCP server, allowing the sandboxed application to run on a completely different machine, with an additional layer of isolation,” the Trail of Bits team said about AppJailLauncher.

This version of the sandbox is for 32-bit versions of Windows and the core component of Windows Defender – the Malware Protection Engine (MsMpEng).

In recent months, Google engineers from the Project Zero have shown how vulnerable this component is, discovering several bugs that could be exploited to gain complete control of vulnerable machines.

Some of these bugs were so dangerous that a simple email or malicious JavaScript file was enough to compromise Windows systems.

Microsoft, on the other hand, has focused in recent years on improving Windows security. Compared to previous versions of the operating system, Windows 10 is extremely well protected.

Microsoft engineers have already sandboxed some Windows applications. For example, the JIT code compiler in Microsoft Edge runs in a sandbox. Applications like Device Guard detect and prevent the exploitation of common vulnerabilities, keeping Windows systems secure.

As many experts who commented on the Trail of Bits experiment pointed out, [1, 2] one reason why Microsoft chose not to use sandboxing in Windows Defender may be related to the potential performance of the application.

The Trail of Bits experiment is simply a demonstration that Windows Defender can be sandboxed but it did not focus on performance-related metrics.

The technical details are described in detail here.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS