Vulnerabilities Detection in the Configurations of MS Windows Operating System

This paper addresses to the technique of the vulnerabilities detection. The proposed methodology is applicable to verify property of the operating system configurations safety. Using our technique it becomes possible to discover security drawbacks in any secure system based on access control model of 'state machine' style. We discuss the Vulnerability Criteria Processing Unit, the automated detection tool, working in MS Windows and calculating the set of vulnerable settings. Through our case study of model checking in Sample Vulnerability Checking (SVC), we show how the proposed technique is applied to verify system security.