Hyper-V performance with Microsoft EMET EAF Feature in VDI and ReCoBS


emet useful remote-controlled browsers systems (recobs) , virtual desktop infrastructure (vdi).

applications protected emet eaf feature run 10 times slower (or @ 10% speed) in hyper-v guests presumably because processor debug registers used. performance counter "hypervisor root virtual processor(*)\debug register accesses/sec" increases few 10 thousands on system when emet eaf protected applications run.

any ideas improve performance without loosing eaf benefits?

the emet documentation doesn't explicitly reference hyper-v, but: “some virtual machines not support debug registers (and consequently eaf). however, eaf option still available configuration if emet being run on machine doesn’t support debug registers. setting option on machines have no effect. be aware of limitation when configuring eaf.“

drm , copy protection (securom and/or safedisc afair) software affected.

references:
aslr bypass mitigated eaf: https://badishi.com/tweaking-metasploit-modules-to-bypass-emet-part-1/
emet forum: http://qa.social.technet.microsoft.com/forums/en/emet/thread/e95141f6-b1d8-4869-9a29-cc8dd321d804
emet 3.0: http://support.microsoft.com/kb/2458544
emet 3.5 tech preview: http://www.microsoft.com/en-us/download/details.aspx?id=30424
isc sans: https://isc.sans.edu/diary/emet+3.5%3a+the+value+of+looking+through+an+attacker%27s+eyes/14797
microsoft emet recommendation example: http://blogs.technet.com/b/msrc/p/january-2013-oob-security-bulletin-q-a.aspx
recobs: https://www.bsi.bund.de/shareddocs/downloads/de/bsi/internetsicherheit/recobslanginfo_pdf.pdf?__blob=publicationfile

thanks

hi,

wish below posts/blog can give information you:

http://blogs.technet.com/b/configmgrteam/archive/2012/05/15/deploying-and-configuring-the-enhanced-mitigation-experience-toolkit.aspx

http://rorymon.com/blog/index.php/tag/enhanced-mitigation-experience-toolkit/

http://social.technet.microsoft.com/forums/zh/emet/thread/e95141f6-b1d8-4869-9a29-cc8dd321d804

regards,


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.



Windows Server  >  Hyper-V



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group