Home > Information Security Tips > Tech tips > How to automate and apply Microsoft Windows 7 AppLocker rules
Security UK Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

TECH TIPS

How to automate and apply Microsoft Windows 7 AppLocker rules


Lisa Phifer
10.18.2009
Rating: --- (out of 5)


Security UK Tips and Expert Advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


In part one of this two-part technical tip, we explored application whitelisting features in Microsoft Windows 7 AppLocker, as well as how to define AppLocker rules. Here, we'll dive into how to automate AppLocker rule generation and how to apply those rules once you have AppLocker up and running.

AUTOMATING APPLOCKER RULE GENERATION
When it comes to defining rules for Windows XP/Vista Software Restriction Policies, admins are largely left to fend for themselves. With AppLocker, Microsoft included a couple of wizards to speed rule generation.

To get you started, a create-default rules wizard generates a trio of AppLocker rules that let everyone run executables only in the Windows and Program Files folders, while letting administrators run executables anywhere. These simple rules do not exploit AppLocker benefits; they create a sandbox in which to learn about AppLocker without accidentally locking yourself (an administrator) out.

To get you really rolling, the rule-creation wizard scours an entire reference PC to find all programs (executables, installers and scripts) and proposes a complete collection of AppLocker rules to allow them. Importantly, that collection maximizes program-rule use, falling back to hash rules only for programs without signatures.

You'll have a chance to preview and edit proposed rules before applying them in one fell swoop -- for example, to add exceptions or permit new program installation from network shares. This wizard speeds rule generation, but must usually be run on one of the PCs to be controlled. (Your Windows Server probably does not have a correct or complete set of reference programs.)

EASE INTO APPLOCKER
Due to its disallow-everything-else stance, take AppLocker out for a test drive using the Local Security Policy snap-in on a Windows 7 PC. Before you start, set the AppID service to start manually so you can easily recover from mistakes by rebooting. Begin with a few very broad allow rules, adding narrow deny rules to develop a feel for how AppLocker works -- including accidental lock-me-out mistakes common to whitelisting. You can also set AppLocker to run in audit-only mode, logging what would happen before changing rules to actively allow or deny programs.

Large enterprises will no doubt struggle with AppLocker due to the sheer complexity of whitelisting thousands of users, hundreds of groups, and the dizzying permutations that result from controlling diverse enterprise applications. However, midmarket businesses may find AppLocker easy enough to use -- and effective enough to make that effort worthwhile. A small office might be controlled entirely through local security policies by using the wizard to inventory each PC and fine-tune proposed rules that reflect what's currently installed there. Most midmarket businesses will prefer to apply AppLocker using centrally defined and maintained GPOs.

Lisa Phifer is vice president of Core Competence Inc. She has been involved in the design, implementation and evaluation of networking, security and management products for more than 25 years, and has advised companies large and small regarding security needs, product assessment, and the use of emerging technologies and best practices.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.co.UK.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Tech tips
Code complexity analysis: How to keep it simple
How to use Windows XP Mode in Windows 7
Understand role-based access control in Microsoft Exchange 2010
Avoid common Web application firewall configuration errors
SQL injection detection tools and prevention strategies
Cross-site scripting explained: How to prevent attacks
How to use Microsoft Windows 7 AppLocker for whitelisting applications
Should you disable IE ESC, or manage it in Windows servers?
Scanning with N-Stalker offers basic Web application security assessment
Microsoft Windows 7 DirectAccess pros and cons

Endpoint and NAC Protection
Look into SIEM services to cut costs, comply with PCI DSS, HIPAA
Voice data security risks on the rise, say experts
The value of booting from a VHD in Windows 7
Thin-client technologies surge thanks to easier security, says Deloitte
A closer look at Internet Explorer 8 security features
USB drive security best practices and processes
First step in forensics: Create a bootable Windows environment CD
Protecting enterprise networks from new mobile application downloads
Four things to remember about server virtualization security concerns
College learns lessons in choosing the right NAC appliance

Platform and OS Security Management
Microsoft issues advisory on new IE security vulnerability
Microsoft patches SMB flaws, Hyper-V problem in big update
Microsoft blue screen affecting few corporate PCs
Microsoft to fix 26 flaws in Windows, Office
Thin-client technologies surge thanks to easier security, says Deloitte
Microsoft issues critical security update, blocks IE 6 attacks
How to use Windows XP Mode in Windows 7
Microsoft to patch single Windows 2000 vulnerability
How to prevent memory dump attacks
Microsoft gives Internet Explorer a major security overhaul

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Centre for the Protection of National Infrastructure  (SearchSecurityUK.com)
Computer Misuse Act 1990  (SearchSecurityUK.com)
Regulation of Investigatory Powers Act  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



UK Data Security Solutions: Data Privacy, Identity Theft, Data Loss
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts