News

'Server Core': Small Footprint, Big Security

IT admins are justifiably excited by the idea of a "server core" in Windows Server 2008, formerly code-named Longhorn Server. The technology, which strips out extraneous functionality to allow just the services needed to run a server in a specific role, promises easier installation and a smaller footprint once set up. It even has implications for security.

Jeff Jones, a Strategy Director in the Microsoft Security Technology Unit, recently matched hard data to the small footprint theory, and came up with some interesting observations and conclusions.

On his TechNet security blog, Jones detailed his experiences installing a server core and a regular, non-server core installation of Windows 2008 on two different partitions on his machine (using the latest beta 3 release). He came up with some startling numbers. The server core installation was less than 1.8GB total, while the full, default Windows 2008 installation was 10.8GB. Jones noted that a server core install is about 16 percent of a full, default install.

So, how does this relate to security? Jones explained: "Can you say 'reduced attack surface area'? The disk space measurement is really just a proxy for the amount of code installed that the IT manager has to worry about in terms of managing security risk. I'm not claiming this was a Microsoft innovation, but it is chock full of security goodness."

Linux servers have had this ability since the beginning, hence the "I'm not claiming this was a Microsoft innovation" comment. Still, it is a big step forward for Microsoft in the security arena.

Server core supports the following roles:

  • Active Directory Domain Services
  • Active Directory Lightweight Directory Services (AD LDS)
  • Dynamic Host Configuration Protocol (DHCP) Server
  • DNS Server
  • File Services
  • Print Server
  • Streaming Media Services

A number of Windows Server attack vectors are eliminated with a server core installation, Jones points out, including Internet Explorer, File Explorer, Media Player, Internet Information Server and the Windows GUI.

For his next experiment, Jones stated he'll go back through vulnerabilities from Windows Server 2003 for the last few years and see how many would have been stopped if a server core-type of installation had been available and used. That should provide some interesting reading.

About the Author

Keith Ward is the editor in chief of Virtualization & Cloud Review. Follow him on Twitter @VirtReviewKeith.

Featured

  • Microsoft Appoints Althoff as New CEO for Commercial Business

    Microsoft CEO and chairman Satya Nadella on Wednesday announced the promotion of Judson Althoff to CEO of the company's commercial business, presenting the move as a response to the dramatic industrywide shifts caused by AI.

  • Broadcom Revamps VMware Partner Program Again

    Broadcom recently announced a significant update regarding its VMware Cloud Service Provider (VCSP) program, coinciding with the release of VMware Cloud Foundation (VCF) 9.0, a key component in Broadcom’s private cloud strategy.

  • Closeup of the new Copilot keyboard key

    Microsoft Updates Copilot To Add Context-Sensitive Agents to Teams, SharePoint

    Microsoft has rolled out a new public preview for collaborative "always on" agents in Microsoft 365 Copilot, bringing enhanced, context-aware tools into Teams channels, meetings, SharePoint sites, Planner workstreams and Viva Engage communities.

  • Windows 365 Cloud Apps Now Available for Public Preview

    Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.