The first GPS policy update in eight years strongly reaffirms the U.S. commitment to GPS technology, a positive signal for companies that develop, market and export related products for commercial, scientific and military uses. The United States will begin an aggressive promotion and tighter coordination oversight of its Global Positioning…
Category: News
Nessus no longer free
Though no company names were mentioned by Nessus leaders during their recent announcement, the popular vulnerability scanner reportedly is used in many commercial security products and services.
I got [responses that ranged from] looks of disbelief to veiled threats in some cases,” said Ron Gula, a Nessus project manager and president and CTO at Tenable Network Security, which also manages the Nessus project. “The vendors who were using Nessus and not contributing anything to it were not happy.”
Jay Jacobson, CEO of Edgeos Inc. in Phoenix, would be screaming if people took credit for his creation for years.
A wide range of testing gizmos are available that can perform security vulnerability assessments, including basic port scanners, network and OS vulnerability assessment tools — even complex Web application penetration testing programs.
Almost all of the Nessus engine is made by those at Tenable, which includes Nessus founder Renaud Deraison as its chief research officer.
“It is difficult to financially justify releasing the work of a corporate developer to the open source community when that developer is supported by thousands of dollars of equipment, salary and benefits,” said Richard Bejtlich, technical director for the Monitoring Operations Division of ManTech’s Computer Forensics and Intrusion Analysis group.
In response to the “exploitation” of his brain child, Deraison, who still leads the Nessus project, announced that Nessus feeds will still be available in three forms: for a fee; for those who register, but with a seven day delay; and under copyright as part of the GNU Public License.
A “Registered Feed” is available for free to the general public, but new plugins are added seven days after they are added to the Direct Feed.
Plugins accepted with a copyright under the GNU Public License will be distributed to the Direct, Registered and GPL feeds at the same time.
http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1034903,00.html
NSA to take lead on Defense info assurance architecture
“We asked NSA to build an IA architecture. NSA did a knock-your-socks-off job of doing this,” Guthrie said today at a lunch the American Council for Technology and Industry Advisory Council sponsored in Arlington, Va.
The IA component calls for integrating security into the GIG by, among other things, authenticating credentials and security clearances. NSA will put together a GIG Information Assurance Portfolio so DOD can have a go-to agency if portions of the grid lack adequate security, Guthrie said.
“NSA will deliver a vision for what it’s going to take to secure the environment,” she said. “This is a blueprint for us to effect this broad IA environment.”
Guthrie also said the Pentagon is getting out of the business of application integration and moving more toward data-level integration.
http://gcn.com/vol1_no1/daily-updates/31383-1.html
Security research suggests Linux has fewer flaws
The conclusion is the result of a four-year research project conducted by code-analysis company Coverity, which plans to release its report on Tuesday.
The project found 985 bugs in the 5.7 million lines of code that make up the latest version of the Linux core operating system, or kernel.
A typical commercial program of similar size usually has more than 5,000 flaws or defects, according to data from Carnegie Mellon University.
“Linux is a very good system in terms of bug density,” said Seth Hallem, CEO of Coverity, a San Francisco company that makes flaw-detection tools for software written in C and C++ programming languages.
Code-analysis tools typically use software-design principles to analyze a program’s source code and flag any possible problems. Microsoft already uses such tools widely in its internal development, and many compilers are starting to include rudimentary versions of the programs as well. The tools are also being used to tame the wild coding prevalent around the Web.
Though Coverity does not have any data about the relative frequency of flaws in Microsoft’s Windows operating system, the latest data will likely feed the debate between the various proponents of Linux, Mac OS X and Windows over which operating system is more secure. A recent report, for example, found that Red Hat Linux had fewer critical flaws than Microsoft Windows. Another research paper, prepared by Forrester Research and hosted on Microsoft’s Web site, favored Windows. Yet another code analysis firm, however, last year analyzed the core networking code used in Linux and found few flaws.
Coverity has not analyzed the source code to Microsoft Windows because the company does not have access to the source code, Hallem said.
Apple Computer’s Mac OS X has a great deal of proprietary programming, but the core of the operating system is based on BSD, an open-source operating system similar to Linux.
Hallem stressed that the research on Linux–specifically, version 2.6 of the kernel–indicated that the open-source development process produced a secure operating system. “There are other public reports that describe the bug density of Windows, and I would say that Linux is comparable or better than Windows,” he said.
A representative of Microsoft could not immediately comment on the Coverity study.
The research suggests that the Linux kernel scored better than run-of-the-mill commercial code.
Proprietary software, in general, has 1 to 7 flaws per thousand lines of code, according to an April report from the National Cybersecurity Partnership’s Working Group on the Software Lifecycle, which cited an analysis of development methods by the Software Engineering Institute at Carnegie Mellon University.
For a 5.7 million-line program, such as version 2.6 of the Linux kernel, that roughly adds up to between 5,700 and 40,000 flaws.
Microsoft uses analysis tools similar to those in Coverity’s study to vet its Windows code. One tool, known as PREfast, runs on each developer’s workstation to check code for simple problems. The other tool, PREfix, is run every night on the Windows source code to catch more complex issues.
Coverity’s Hallem acknowledged that by running similar tools to its own, Microsoft likely had reduced the number of defects in Windows. Coverity plans to provide regular bug analysis reports on Linux and make a summary of the results available to the Linux developer community.
http://news.com.com/Security+research+suggests+Linux+has+fewer+flaws/2100-1002_3-5489804.html?tag=nefd.top
Chinese cybercops ‘nailing virus writers’
The Chinese antivirus police team will visit the Kaspersky Labs offices in Moscow next week to discuss virus development.
“China has worked effectively in fighting virus writers,” said Natalya Kaspersky, chief executive of Kaspersky Labs, on Thursday. “They are much more active than anyone. They have special antivirus police that co-operates with industry. They want to learn more and I think that’s a good practice. They regularly hire people and really seem to care about viruses.”
But she added that hi-tech crime police in other countries are failing to perform as well as the Chinese in hunting virus writers. “European police have realised the problem, but don’t know what to do about it because it’s a virtual problem. I think they have a lot of work to do.”
Kaspersky said she wanted her company to work more closely with government and police forces around the world. “We are very proud that we caught one virus writer,” she said. “But the sentence was something like [a fine of] $300. It was the first case of its kind. The problem for us is that in Russian law, you have to prove the damage someone has done. How could you find a witness to prove someone started an attack?”
The UK’s National Hi-Tech Crime Unit is dedicated to fighting organised online crime, but currently individual users may only report isolated virus attacks to their local police station. Russia’s counterpart to the NHTCU is its Ministry of Internal Affairs K Department.
Last week, security lobbyist EURIM said it was pushing the government to employ IT professionals as special constables. The group said that the proposed Serious Organised Crime Agency should be a central point of contact for computer crimes.
http://news.zdnet.co.uk/0,39020330,39180202,00.htm
Asia Pacific: Combat cyber crime, firms told
Speaking at the ‘Crime and Policing in Malaysia’ forum at Universiti Sains Malaysia (USM) in Penang, Othman said with the fast moving pace in information technology (IT), it was important for all parties to work together.
He added when crimes were investigated, physical evidence such as fingerprints, marked bills, DNA or video footage are collected but in cyberspace, global networks lacked effective identification mechanisms.
“Therefore, it is important for the police to learn from the private sector about intrusion attempts and susceptibilities,” said Othman.
http://penang.thestar.com.my/content/news/2004/12/7/9550869.asp