The Enhanced Mitigation Experience Toolkit, or EMET for short, is a security tool provided by Microsoft. It is probably the single best piece of security software for Windows computers. Why? Because it takes programs that haven’t been keeping up with security and forces them to use the techniques of the last decade.

Security is a constantly evolving field. In the last decade we’ve had major changes in the way we secure programs. Mitigation techniques like DEP and ASLR have made their way into operating systems, but some programs can lag behind in implementing them. These security techniques are critical in preventing attacks.

EMET is built to bring those programs up to speed. It secures programs, and the system, by forcing them to use techniques such as DEP, SEHOP, ForceASLR and others. Many attacks in the wild can be prevented with EMET, and it’s a must-have for anyone looking for security on a Windows system.

I’ve written a guide for setting up EMET 3.0, Microsoft’s latest stable release of the program. I highly suggest you read it, and set EMET up on your system, as, in my opinion, it’s one of the first steps to having a secure Windows system.

EMET In Practice

I think it’s worth demonstrating exactly how secure EMET will make your Windows system. So I’ll show you some actual examples from in-the-wild attacks against systems where EMET could have prevented the attack, and I’ll show you definitive research showing what happens to a system running EMET when an attacker wants in.

First up is an attack against Adobe Reader. A popular PDF reader that has a poor security record. Recently Adobe has taken significant steps to secure Reader and they have implemented a sandbox. But a recent attack in the wild has bypassed the sandbox, and allowed attackers to gain control over the program. Does EMET stop it?

Yep. It does. In fact, Microsoft’s recommendation was to force Reader to use EMET, which would prevent the exploit. As there was no patch out for this attack EMET was the easiest go-to solution.

Microsoft and Adobe have both suggested using EMET to prevent attacks in the past.

Another exploit, this time in the popular Internet Explorer, was stopped by EMET. Microsoft once again urged Internet Explorer users to install EMET, as it would protect them from this attack.

Microsoft research has shown EMET can have a major effect on exploits.

Deploying EMET drastically reduces the effectiveness of exploits on Windows XP. Only 21 of 184 exploits succeeded on Windows XP with EMET deployed.

Keep in mind that EMET has improved since this report, and is even more effective on Vista/7/8.

So What’s The Downside?

A lot of readers will probably be asking “is this too good to be true?” Many assume that EMET must have some huge performance hit, or cause massive system instability. The truth is that these mitigation techniques will have virtually no performance impact, and, if you follow my guide, you should have virtually no instability issues. It is incredibly easy to set EMET up, and there is almost no reason not to.

Can problems occur? Yes. But if you follow my guide, and you stick to the XML provided by Microsoft and built into EMET, you are incredibly unlikely to come across programs crashing.

So, again, if you are looking to secure Windows, I would say that EMET is the easiest way to do so. Follow the guide and get it installed. Every users should.



blog comments powered by Disqus

Published

03 March 2013

Category

security