Kernel Patch Protection: Difference between revisions

Content deleted Content added
No edit summary
Tags: Mobile edit Mobile web edit
m Disambiguating links to Symantec (link changed to NortonLifeLock; link changed to NortonLifeLock; link changed to NortonLifeLock; link changed to NortonLifeLock) using DisamAssist.
Line 133:
 
===Third-party applications===
Some computer security software, such as [[McAfee]]'s [[McAfee VirusScan]] and [[NortonLifeLock|Symantec]]'s [[Norton AntiVirus]], worked by patching the kernel on x86 systems.{{citation needed|reason=but NIS2010/11 works on my version of WIn7x64 :/|date=January 2011}} Anti-virus software authored by [[Kaspersky Lab]] has been known to make extensive use of kernel code patching on [[x86]] editions of Windows.<ref>{{cite web
|url=http://uninformed.org/index.cgi?v=4&a=4&p=10
|author=Skywing
Line 164:
|accessdate=30 November 2006
|year=2006
|publisher=[[NortonLifeLock|Symantec]]
}}</ref> and Norton 2010 range and beyond<ref>{{cite web
|url=http://us.norton.com/internet-security
Line 170:
|accessdate=26 January 2011
|year=2011
|publisher=[[NortonLifeLock|Symantec]]
}}</ref> worked on x64 editions of Windows despite KPP's restrictions, although with less ability to provide protection against zero-day malware.
Antivirus software made by competitors [[ESET]],<ref>{{Cite web|url=http://www.eset.com/products/64bit.php|title=High-performance threat protection for the next-generation of 64-bit computers|last=|first=|date=2008-11-20|publisher=ESET|archive-url=https://web.archive.org/web/20081120071411/http://www.eset.com/products/64bit.php|archive-date=2008-11-20}}</ref> [[Trend Micro]],<ref>{{cite web
Line 219:
 
===Weaknesses===
Because of the design of the Windows kernel, Kernel Patch Protection cannot completely prevent kernel patching.<ref name="skape"/> This led the computer security providers [[McAfee]] and [[NortonLifeLock|Symantec]] to say that since KPP is an imperfect defense, the problems caused to security providers outweigh the benefits, because [[malicious software]] will simply find ways around KPP's defenses and third-party security software will have less freedom of action to defend the system.<ref name="Samenuk"/><ref name="Gewirtz">{{cite news
|last=Gewirtz
|first=David