What is user application hardening?
Where it stops an attack.
- The attack A malicious web ad or document tries to launch another program or inject code.
- Stopped here Browsers block web ads and Java, and Office and PDF software can’t start other programs.
- The result The page or file has nothing to work with.
Application hardening maturity levels
What changes at each level.
Each level includes everything in the one before. A plain-English summary, not the requirement text. ASD Essential Eight Maturity Model (November 2023)
How to harden browsers, Office and PDF software
Protection first, disruption last.
- 01
Baseline your browsers
One or two approved browsers, managed centrally, with ads and legacy plugins blocked. - 02
Turn on attack surface reduction rules
Microsoft Defender rules stop Office and PDF apps launching other programs. Audit first, then block. - 03
Remove legacy components
Internet Explorer 11, PowerShell 2.0 and old .NET Framework versions come out. - 04
Lock and log
Settings enforced by policy, with PowerShell and process events sent to a central log.
Common application hardening mistakes
Where rollouts go wrong.
-
Unmanaged browsers
A browser staff installed themselves ignores every setting.
-
Untested ASR rules
Some rules affect add-ins and line-of-business tools. Audit mode first.
-
Forgetting PDF software
Office locked down, an old PDF reader left wide open.