Daar ama dami go'doominta xudunta ah iyo daacadnimada xusuusta gudaha Windows 11/10
Weerarada internetka ayaa isbedelay dhowrkii sano ee la soo dhaafay. Hackers-ku hadda way la wareegi karaan PC-gaaga oo way xidhi karaan faylasha ilaa aad diyaar u tahay inaad lacag siiso. Weerarada noocaan ah waxaa loo yaqaan Ransomware , waxayna adeegsadaan faa'iidooyin heer kernel ah oo isku dayaya in ay ku socodsiiyaan malware-ka leh mudnaanta ugu sareysa, tusaale, WannaCry iyo Petya ransomware. Si loo yareeyo weerarada noocaan ah, Microsoft waxa ay soo saartay qaab kuu ogolaanaya inaad awood u siiso Core Isolation iyo Integrity Memory(Core Isolation and Memory Integrity) si looga hortago weerarradan.
Xarunta Amniga Difaaca(Defender Security Center) Windows ayaa bixisa sifadan. Waxaa loogu yeeraa Ammaanka Aaladda ,(Device Security, ) waxa ay bixisaa ka warbixinta heerka iyo maaraynta sifooyinka amniga lagu dhex dhisay aaladahaaga – oo ay ku jiraan sifada beddelka si loo bixiyo ilaalin la xoojiyey. Si kastaba ha ahaatee, kuma shaqeeyo heerka software; qalabku wuxuu u baahan yahay inuu sidoo kale taageero. Farsameeyahaagu waa inuu taageeraa Virtualization, kaas oo awood u siinaya Windows 11/10 PC inuu ku socodsiiyo codsiyada weelka, si aanay u helin qaybaha kale ee nidaamka.
Qalabkaagu waa inuu buuxiyaa shuruudaha badbaadada qalabka caadiga ah Tani waxay la macno tahay in aaladdaadu ay taageerto daacadnimada xusuusta iyo go'doominta xudunta ah oo waliba:
- TPM 2.0 (sidoo kale loo yaqaan processor-kaaga amniga)
- Boot sugan waa la furay
- DEP
- UEFI MAT
Ka yeel Go'doominta Muhiimka(Core Isolation) ah & daacadnimada xusuusta(Memory Integrity) gudaha Windows 11
Waxay u badan tahay inay tahay habka ugu fudud ee lagu suurtagelin karo ama lagu joojin karo Amniga(Security) ku saleysan Virtualization gudaha Windows 11 . Si kale haddii loo dhigo, waxaad u baahan tahay inaad awood u yeelatid go'doominta Core(enable Core isolation) si loo sameeyo. Taas, samee waxyaabaha soo socda:
- Ka raadi amniga daaqadaha (windows security ) sanduuqa raadinta Taskbar.
- Guji(Click) natiijada raadinta shakhsi ahaaneed.
- U beddelo tab ammaanka aaladda.(Device security)
- Guji ikhtiyaarka faahfaahinta go'doominta Core .(Core isolation details )
- Daar badhanka daacadnimada xusuusta si aad u shido.(Memory integrity )
- Dib u bilaw kombayutarkaga
Ka yeel go'doominta xudunta(Core Isolation) ah iyo daacadnimada xusuusta(Memory Integrity) gudaha Windows 11/10
- Soo gal maamule ahaan oo fur Xarunta Amniga Difaacaha Windows(Windows Defender Security Center)
- Raadi ikhtiyaarka Amniga Aaladda .(Device Security)
- Halkan waa inaad ka hubisaa haddii Go'doonka Core(Core Isolation) ee Virtualization ka yahay kombuyutarkaaga.
- Go'doominta xudunta ahi waxa ay (Core isolation)bixisaa(y) sifooyin sugan oo ku salaysan makhluuqaad si loo ilaaliyo qaybaha ubucda ah ee qalabkaaga.
- Guji(Click) faahfaahinta go'doominta xudunta(Core) ah, waxaana lagu siin doonaa si aad awood ugu yeelato daacadnimada xusuusta(Memory Integrity) .
Xumaannimada xusuusta(Memory integrity) (Hypervisor-la ilaaliyo daacadnimada koodhka) waa astaanta amniga ee go'doominta Core taasoo ka hortagaysa weerarrada gelinta kood xaasidnimo ah hababka amniga sare. Daar(Toggle) si aad u shido
Marka la furo, waxay ku weydiin doontaa inaad dib u bilowdo PC si aad si buuxda u awood u yeelato Integrity Memory(Memory Integrity) .
Haddii mardambe, aad la kulanto arrimo ku habboon codsiga, waxaa laga yaabaa inaad u baahato inaad tan damiso.
la xidhiidha(Related) : daacadnimada xusuusta ayaa cirroobtay ama ma dami doonto/ dami mayso .
Karti ama demi go'doominta xudunta(Core Isolation) ah iyo daacadnimada xusuusta(Memory Integrity) adoo isticmaalaya Diiwaanka
Waxa kale oo aad isticmaali kartaa Diiwaanka(Registry) , si aad awood ugu yeelatid ama aad u joojisid daacadnimada xusuusta(Memory) go'doominta Core addoo isticmaalaya (Core)Registry Editor , raac talaabooyinkan:
- Riix Win+R si aad u furto Run dialog.
- Ku qor regedit oo ku dhufo badhanka Gelida .(Enter)
- Guji ikhtiyaarka Haa .(Yes)
- U gudub Scenarios gudaha HKEY_LOCAL_MACHINE .
- Midig ku dhufo Scenarios > New > Key .
- U sheeg sida HypervisorEnforcedCodeIntegrity .
- Midig ku dhufo> New > DWORD (32-bit) Value .
- U magacow(Enabled) sidii karti .
- Laba-guji si aad u dejiso xogta Qiimaha sida (Value)1 si aad u awood u yeelato iyo 0 si aad u damiso.
- Guji badhanka OK
- Dib u bilaw kombayutarkaga
Si aad wax badan uga barato tillaabooyinkan, sii wad akhriska.
Ka taxaddar:(Precaution: ) Kahor intaadan u dhaqaaqin tillaabooyinka REGEDIT , ha ilaawin inaad abuurto barta Soo celinta Nidaamka .
Si aad u bilowdo, taabo Win+R si aad u furto Run dialog, ku qor regedit, oo ku dhufo badhanka Enter . Haddii degdega UAC uu ka soo muuqdo shaashaddaada, dhagsii ikhtiyaarka Haa si aad u (Yes )furto Tifaftiraha Diiwaanka .
Marka xigta, u gudub jidka soo socda:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios
Midig ku dhufo furaha Muuqaallada> Cusub (Scenarios )New > Key , oo u magacow HypervisorEnforcedCodeIntegrity(HypervisorEnforcedCodeIntegrity) .
Markaa, waa inaad abuurtaa REG_DWORD qiime. Taas awgeed, midig-guji HypervisorEnforcedCodeIntegrity > New > DWORD (32-bit) Value , oo u magacow(Enabled) sida karti .
Sida caadiga ah, waxay la socotaa xogta Qiimaha (Value)0 , taasoo la micno ah inay naafo tahay. Si kastaba ha noqotee, haddii aad rabto inaad awood u yeelatid shaqadan, laba jeer guji si aad u dejiso xogta Qiimaha sida (Value)1 .
Guji badhanka OK oo dib u bilow kombayutarkaga.
Taasi waxay tidhi, waxaa jira laba ikhtiyaar oo kale oo laga yaabo in la heli karo iyadoo ku xiran qalabka kombuyuutarkaaga.
- Processor-ka ammaanku(Security Processor) waxa uu soo baxaa oo keliya haddii aad haysato TPM oo la heli karo qalabkaaga PC. Waa chips discrete oo ay OEM -yada ku iibiyeen Motherboard-ka kombiyuutarka . Si aad uga faa'iidaysato TPM , OEM waa inay si taxadar leh u dhexgelisaa qalabka nidaamka iyo qalabaynta TPM si ay u soo dirto amarada ugana falceliso jawaabaheeda. TPM(TPMs) -yada cusub waxay sidoo kale ku siin karaan faa'iidooyin amni iyo gaar ah qalabka nidaamka laftiisa. Markaa iska hubi inaad kuwaas oo dhan iska hubiso haddii aad iibsanayso PC cusub.
- Boot aamin(Secure Boot) ah waxay ka hortagtaa koodka xaasidnimada ah in lagu shubo ka hor OS-kaaga. Way adagtahay in la dildilaaciyo laakiin leh kabo sugan ayaa la daryeelay.
Windows 11/10 waxa kale oo ay bixisaa Hypervisor Protected Code Integrity ( HVCI ) marka aad ku bilowdo rakibo nadiif ah. Kuwa ku jira qalabkii hore, waxay yeelan doonaan awood ay ku doortaan boostada cusboonaysiinta iyagoo isticmaalaya UI ee Xarunta Amniga Difaaca Windows(Windows Defender Security Center) ( WDSC ). Kobcintani waxay hubin doontaa in habka kernel-ka ee xaqiijiya daacadnimada koodka uu ku socdo jawi runtime sugan oo sugan.
Akhriso(Read) : Amniga ku salaysan fakarka lagama shaqaynin Windows 11(Virtualization-based Security not enabled in Windows 11) .
Related posts
U oggolow ilaalinta codsiyada suurtagalka ah ee aan la rabin gudaha Windows 11/10
Sida galka looga saaro iskaanka difaaca Windows gudaha Windows 11/10
Ma daari karo Windows Defender gudaha Windows 11/10
Sida loo furo Xarunta Amniga Windows gudaha Windows 11/10
Samee iskaanka khadka tooska ah ee Difaaca Windows wakhtiga bootinta gudaha Windows 11/10
Hagaaji Crypt32.dll lagama helin ama khalad ka maqan Windows 11/10
Demi dejinta daacadnimada xusuusta haddii Windows aysan soo dejin karin darawalka
Sida loo beddelo kamaradaha caadiga ah ee kumbuyuutarka Windows 11/10
Sida loo hagaajiyo 100% Disk, CPU High, isticmaalka xusuusta sare ee Windows 11/10
Sida loo nadiifiyo Memory Cache gudaha Windows 11/10
Dejinta isku xidhka oo aan shaqaynayn ama ka cirroonayn Windows 11/10
Hagaaji Chrome sare ee CPU, Memory ama isticmaalka Disk gudaha Windows 11/10
Explorer.exe High Memory ama isticmaalka CPU gudaha Windows 11/10
Tweak Core Parking, dejimaha cabbiraadda inta jeer ee CPU gudaha Windows 11/10
Sida loo suurto geliyo ama loo joojiyo astaanta abka Archive gudaha Windows 11/10
Sida loo isticmaalo Charmap iyo Eudcedit qalabyada ku dhex dhisan ee Windows 11/10
Waa maxay faylka PLS? Sida loo abuuro faylka PLS gudaha Windows 11/10?
Software-ka ugu fiican ee ISO Mounter ee bilaashka ah ee Windows 11/10
Qalabka dib-u-ciyaarista HDMI oo aan ka muuqanayn Windows 11/10
Sida loo furo guryaha nidaamka ee Control Panel gudaha Windows 11/10