请记住,有特定的注册表键只适用于英特尔和AMD。因此,您可能需要查看您的环境需要哪些选项。例如这里启用的修复幽灵变种2和崩溃有三个你需要添加注册表键。如果您想要添加保护投机商店绕过幽灵2和崩溃V3有一系列稍有不同的需要添加注册表条目。现在一旦你设置这些你想检查注册表条目的status of it. Now I'm doing this on a plain vanilla server 2016 where I've done not done any mitigation whatsoever right now. And you want to install the module speculative speculation control. This is enabled on Server 2016 and 2019. For older servers you'll need to go to TechNet and download the script there. You want to install the module on the server. And make sure it's enabled. Once you've set the power shell script policy you want to import the module and then go ahead and run it on your server. And see what the resulting settings are. Again this is on a default. I have not done anything to this server this is a server in HyperV hosted. And you can see that I actually am not fully protected.
这取决于您的环境。当您启用这些缓解措施时,会有一些性能影响。所以检查一下你的环境。检查你自己的风险水平。检查一下你的设备和防火墙是否有设置,或者它们是否能确定你是否受到这些设置的攻击。请记住,到目前为止,据我所知,我还没有看到任何活跃的使用这些推测侧技术的狂野攻击。有很多关于概念的证明。关于这类攻击有很多信息,但老实说,我在使用这类攻击的狂野攻击中没有看到真正的活跃。如果你觉得因为性能问题而不启用所有功能。没关系,这是你需要在你的环境中做的风险和分析。 So until next time this is Susan Bradley for CSO Online. Thank you for being an insider.