Ungayinika kanjani amandla i-VBS kusuka ku-UEFI kuWindows igxathu negxathu

Isibuyekezo sokugcina: 17/03/2025

  • Ukuphepha okusekelwe kwi-Virtualization-based (VBS) kuthuthukisa ukuvikelwa kwesistimu.
  • Ukunika i-VBS amandla kudinga i-UEFI ne-TPM 2.0 hardware ehambisanayo.
  • Inganikwa amandla ku-BIOS, Windows Registry, kanye ne-Group Policy.
  • Kunezindlela zokuqinisekisa ukuthi i-VBS yenziwe ngendlela efanele yini.
I-VSB

La ukuphepha okusekelwe kwi-virtualization (I-VBS) ku-Windows isici esithuthukisa ukuvikelwa kwesistimu ngokudala indawo evikelekile neyodwa. Kodwa ngoba vumela i-VBS kusuka ku-UEFI futhi ukusizakala ngalesi sici, kuyadingeka ukuhlangabezana nezingxenyekazi zekhompuyutha ezithile nezimfuneko zokumisa ohlelweni lokusebenza.

Kulesi sihloko sihlola ngokuningiliziwe ukuthi singayivula kanjani Ukuphepha Okusekelwe Kwi-Virtualization kusuka ku-UEFI, yiziphi izinyathelo okufanele uzilandele ukuze uhlole isimo sayo nokuthi ungazixazulula kanjani izinkinga ezingenzeka ngesikhathi sokucushwa.

Iyini i-Virtualization-Based Security (VBS)?

Ukuphepha Okusekelwe Kwi-Virtualization (VBS) i Ubuchwepheshe bokuphepha beWindows esetshenziswa yi-hypervisor yesistimu ukudala indawo evikelekile ngaphakathi kwenkumbulo. Ngale ndlela, idatha yesistimu ebalulekile ivikelekile ezinsongweni ezingaba khona. Lesi sici riqinisa ukuvikeleka kwe-kernel futhi ikhawulela ukufinyelela kuzinqubo ezingagunyaziwe.

Enye yezingxenye ezibalulekile ze-VBS yi- Ubuqotho Benkumbulo, okuvimbela ukwenziwa kwekhodi enonya ngokuhlola ukufaneleka kwabashayeli namafayela esistimu ngaphambi kokuwavumela ukuthi asebenze.

Okuqukethwe okukhethekile - Chofoza Lapha  Ngingaxhumana kanjani nosekelo lobuchwepheshe noma ithimba lesevisi yamakhasimende lohlelo lokusebenza lwe-VRV?

Izidingo zokuvula i-VBS

Ngaphambi kokuvumela i-VBS ku-UEFI, qiniseka ukuthi ikhompuyutha yakho ihlangabezana nalezi zidingo ezilandelayo:

  • I-Firmware ye-UEFI: : Kudingeka ukuthi i-BIOS isethelwe kumodi ye-UEFI esikhundleni se-Legacy.
  • I-TPM 2.0: I-Trusted Platform Module kumele inikwe amandla ku-BIOS.
  • Secure Boot: Le nketho ye-BIOS kufanele ivunyelwe.
  • Ukuvikelwa kwe-DMA: Ithuthukisa ukuphepha ngokukhawulela ukufinyelela kumadivayisi angaphandle.

Ngaphandle kwalokhu, ukuze uhlole ukuthi isistimu yakho iyahambisana yini ne-VBS, udinga ukulandela lezi zinyathelo:

  1. Sebenzisa isinqamuleli sekhibhodi Win + R, kubhala msinfo32 bese ucindezela Faka.
  2. Bheka isigaba «Ukuvikeleka okusekelwe ekwenzeni izinto ezibonakalayo«. Uma ibonisa njengokuthi "Iyasebenza," kusho ukuthi isivele yenziwe yasebenza.

Uma ufuna ukufunda kabanzi mayelana nendlela yokunika amandla i-virtualization kusistimu yakho, ungabheka umhlahlandlela wethu kokuthi Nika amandla i-virtualization yehadiwe ku-Windows 11.

izinhlobo ze-bios

Ungayivula kanjani i-VBS kusuka ku-BIOS (UEFI)

Ukuze unike amandla i-VBS kusuka ku-UEFI (kusuka ku-BIOS), landela lezi zinyathelo:

  1. Qala kabusha ikhompyutha yakho bese ufinyelela i-BIOS ngokucindezela F2, F10, Del noma Esc, kuye ngomkhiqizi.
  2. Kumenyu yezilungiselelo, bheka inketho “Imodi yokuqalisa»bese ushintshela ku UEFI uma usekumodi Yefa.
  3. Thola inketho "I-TPM 2.0» futhi uyisebenzise uma ingavunyelwe.
  4. Nika amandla inketho ethi «Secure Boot".
  5. Londoloza izinguquko bese uqala kabusha ikhompuyutha.
Okuqukethwe okukhethekile - Chofoza Lapha  Yiziphi izinketho zokuhlanganisa i-IM ezitholakalayo ku-Alexa?

Nika amandla i-VBS ku-Windows Registry

Uma ukhetha ukunika amandla i-VBS usebenzisa i Ukubhaliswa kweWindows, yenza lezi zinyathelo ezilandelayo:

  1. cindezela Win + R, kubhala regedit bese ucindezela Faka.
  2. Zulazulela endleleni elandelayo:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard
  3. Thola noma dala inani le-DWORD eliqanjwe ngokuthi "Nika amandla iVirtualizationBasedSecurity» futhi inikeze inani 1.
  4. Endaweni efanayo, lungisa "I-DingaPlatformSecurityFeatures"ukuze 3 (yokuvula ibhuthi evikelekile nokuvikelwa kwe-DMA).
  5. Londoloza izinguquko bese uqala kabusha ikhompuyutha yakho.

Ilungiselela i-VBS Ukusebenzisa Inqubomgomo Yeqembu

Abaphathi besistimu bangakwazi futhi ukunika amandla i-VBS besebenzisa i-Group Policy:

  1. Vula Umhleli Wenqubomgomo Yeqembu ngokubhala gpedit.msc kumenyu yokuqala.
  2. bese uya ku Ukusethwa kweqembu.
  3. Lapho siyakhetha Izifanekiso Zokulawula > Isistimu > Isigadi Sedivayisi.
  4. Vula inketho ethi «Nika amandla ukuvikeleka okusekelwe ekubonweni»bese ukhetha «Kunikwe amandla".
  5. Kuhlu lokudonsela phansi, khetha “Inikwe amandla ngokukhiya kwe-UEFI".
  6. Londoloza izinguquko bese uqala kabusha ikhompuyutha.

Ungahlola kanjani ukuthi i-VBS iyasebenza

Kunezindlela ezimbalwa zokuqinisekisa ukuthi i-VBS yenziwe ngendlela efanele yini:

  • Ukusebenzisa i-msinfo32, ibheka isigaba esithi "Virtualization-based Security". Uma ikumodi "Yokusebenza", bese iyasebenza.
  • I-Mediante PowerShell, esebenzisa umyalo olandelayo ku-PowerShell ngezimvume zomlawuli: (Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard).SecurityServicesRunning.Uma okukhiphayo kubonisa "2«, kusho ukuthi i-VBS iyasebenza.
  • Ngesibukeli Somcimbi. Vula umcimbivwr.msc bese uya kokuthi “Amalogi EWindows > Isistimu”. Hlunga ngokuthi “WinInit” ukuze ubone ukuthi i-VBS inikwe amandla ngempumelelo yini.
Okuqukethwe okukhethekile - Chofoza Lapha  Ungawuqopha kanjani umhlangano we-RingCentral?
vumela i-VBS kusuka ku-UEFI
Ungayinika kanjani amandla i-VBS kusuka ku-UEFI kuWindows

Ukuxazulula inkinga Ukuqalisa kwe-VBS

Uma uhlangabezana nezinkinga lapho uzama ukwenza i-VBS isebenze ku-UEFI, zama izixazululo ezilandelayo:

  • I-TPM 2.0 ikhutshaziwe: Faka i-BIOS futhi uqiniseke ukuthi ivuliwe.
  • Imodi yefa ku-BIOS: Shintsha izilungiselelo zibe i-UEFI.
  • Isistimu ayilayishi ngemva kokwenza kusebenze: Khubaza i-VBS kuRegistry noma Inqubomgomo Yeqembu bese uqalisa kabusha.
  • Abashayeli abangahambisani: Buyekeza abashayeli ukusuka kuSiphathi Sedivayisi.

Ngokulandela lezi zinyathelo ngendlela efanele, kufanele ukwazi ukunika amandla i-VBS kusuka ku-UEFI, okungukuthi vumela i- ukuphepha okusekelwe kwi-virtualization ngaphandle kwezinkinga. Lobu buchwepheshe buyithuluzi elibalulekile lokuthuthukisa ukuvikeleka kwesistimu yakho ezinsongweni ezithuthukile.