background image

16

Frequently Asked Questions

What is XD?

Execute Disable Bit (XD) functionality can prevent certain types of buffer overflow attacks when 

used with a supporting operating system and system BIOS. XD allows the processor to classify 

areas in memory where application code can and cannot execute. When a virus or worm 

attempts to insert code in the buffer, the processor disables code execution, preventing damage 

or virus or worm propagation.
This feature works with Microsoft's Data Execution Prevention software to help prevent execution 

of malicious software such as a virus or a worm. The user benefits from increased network 

security as the malicious code cannot propagate or spread to infect more computers. Support 

staff also benefits from much improved containment and easier eradication of unwanted 

software.

What is NX?

NX is the term AMD uses for XD.

What is DEP?

Data Execution Prevention (DEP) is the terminology Microsoft uses for XD and NX. In Windows XP 

Service Pack 2 (SP2), Microsoft introduced DEP, which is a processor feature that prevents 

execution of code in memory that is marked as data storage. This limits the “attack surface”, 

specifically for buffer overrun vulnerabilities, where an attacker typically overruns a buffer with 

code and then executes this code. Unlike a firewall or antivirus program, DEP does not help 

prevent harmful programs from being installed on your computer. Instead, it monitors your 

programs to determine whether they use system memory safely. 
Windows XP SP2 uses two types of DEP:

• Hardware-enforced DEP - Hardware-enforced DEP provides data protection with hard-

ware (processor) support, requiring use of Windows XP SP2 and a processor that sup-

ports XD/NX.

• Software-enforced DEP - Software-enforced DEP is an additional set of DEP security 

checks built into Windows XP SP2 that can be used with any processor that supports 

Windows XP SP2. Software-enforced DEP is a more limited form of protection for the 

exception handling mechanisms in Windows. It is used when hardware-enforced DEP is 

not available, usually because the processor does not support XD or is disabled in BIOS.

Do they work together or individually? 

XD/NX works in conjunction with Microsoft's Data Execution Prevention (DEP) software to help 

prevent malicious software such as a virus or a worm from executing. The user benefits from 

increased network security as the malicious code cannot propagate or spread to infect more 

machines. Support staff also benefit from much improved containment and easier eradication of 

unwanted software.

How is XD different from NX?

XD and NX are functionally the same, but they use different hardware implementations. 

Содержание xw4200

Страница 1: ...om virus attacks 5 What are the required components for XD NX to function 5 How do I control the DEP functionality on my computer 8 DEP Level Chart 9 Data Execution Prevention Tab No XD NX Processor 1...

Страница 2: ...e European Commission in Brussels to name a few Microsoft s Windows XP Service Pack 2 includes multiple security improvements Network protection Memory protection Email handling Web browsing security...

Страница 3: ...helps prevent these attacks by intercepting them and displaying the DEP message box Hardware enforced DEP relies on processor hardware to mark memory with an attribute that indicates that code should...

Страница 4: ...ed for arith metic calculations or to keep track of internal operations In normal system operations code is not typically executed from the default heap and stack Hardware enforced DEP detects code th...

Страница 5: ...essors for the desktop market starting with the E0 stepping of the Prescott Pentium 4 processor Both Intel Pentium 4 and Celeron processors have XD support Using Intel s new pro cessor naming scheme a...

Страница 6: ...stems Default NX support is disabled for Transmeta systems The BIOS for Intel 915 and Intel 945 based desktop systems uses the CPUID instruction to look for the Exe cute Disable bit to determine if XD...

Страница 7: ...essors in the following product line not all systems available in all regions dx5150 The BIOS for the bc1000 disables NX support for the Transmeta processor There is no option to enable NX The followi...

Страница 8: ...d to a program to provide an enhancement and installing it with the application All program and services except those I select This option equates to the OptOut policy which allows a user to select ap...

Страница 9: ...Off No hardware or software enforced DEP is available for any part of the system The processor will not run in PAE mode unless a PAE switch is present in the BOOT INI OptIn Default Hardware and softw...

Страница 10: ...event Windows XP SP2 from using DEP set the operating system to alwaysoff in the BOOT INI file Software Enforced DEP Software enforced DEP is a set of DEP security checks built into Windows XP SP2 tha...

Страница 11: ...nd software enforced DEP Unfortunately at this time you can only test hardware enforced DEP because Microsoft has not yet supplied the tools to test software enforced DEP You can test hardware enforce...

Страница 12: ...em when it expects a 32 bit PTE but instead gets a 64 bit PTE Driver cannot DMA properly with a 64 bit physical addresses To a lesser extent some drivers create code in real time These drivers encount...

Страница 13: ...ATI Catalyst Control Center Exception error Add to exclusion list ATI Driver Setup exe Exception error during installation Add to exclusion list Broadcom Management Apps Exception error Add to exclusi...

Страница 14: ...Add to exclusion list Microsoft Office Pro 2003 Exception error Add to exclusion list Microsoft Office SB 2003 Exception error Add to exclusion list Norton Anti Virus Exception error Add to exclusion...

Страница 15: ...ve afterwards Windows Catalog Exception error Add to exclusion list Driver Effect Creative Audigy 2NX Exception error during installation Add to exclusion list HP Deskjet 450ci Driver Prints out blank...

Страница 16: ...ns a buffer with code and then executes this code Unlike a firewall or antivirus program DEP does not help prevent harmful programs from being installed on your computer Instead it monitors your progr...

Страница 17: ...applications or drivers that attempt to execute out of data memory You should test your images before deploying XD NX If a problem does occur with an application driver associated with a trusted softw...

Страница 18: ...e same methods you use to protect all operating system and BIOS settings For example you can use Setup passwords to control who can change items in F10 Setup Also you can allow only users with adminis...

Страница 19: ...nging is the chipset changing as well For Intel based systems newer chipsets starting with the i915 chipset provide support for XD Will the system board change with the processor change Intel chipset...

Страница 20: ...ly test software enforced DEP HP encourages you to perform your own validation if you plan to use your own image or proprietary software What does it mean when XD NX is disabled but the DEP is set for...

Страница 21: ...vices Nothing herein should be construed as constituting an additional warranty HP shall not be liable for technical or editorial errors or omissions contained herein HP Hewlett Packard and the Hewlet...

Отзывы: