<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Enterprise Linux Log &#187; Security</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/enterprise-linux/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/enterprise-linux</link>
	<description>A SearchEnterpriseLinux.com blog</description>
	<lastBuildDate>Mon, 20 May 2013 17:16:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Researchers boot one million Linux kernels as virtual machines</title>
		<link>http://itknowledgeexchange.techtarget.com/enterprise-linux/researchers-boot-one-million-linux-kernels-as-virtual-machines/</link>
		<comments>http://itknowledgeexchange.techtarget.com/enterprise-linux/researchers-boot-one-million-linux-kernels-as-virtual-machines/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 17:33:22 +0000</pubDate>
		<dc:creator>ITKE</dc:creator>
				<category><![CDATA[botnets]]></category>
		<category><![CDATA[HPC]]></category>
		<category><![CDATA[Linux kernel]]></category>
		<category><![CDATA[Sandia]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Thunderbird supercomputing cluster]]></category>
		<category><![CDATA[Virtualization]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/enterprise-linux/?p=767</guid>
		<description><![CDATA[In a feat of Linux strength, computer scientists at Sandia National Laboratories in Livermore, Calif., announced that they had run more than a million Linux kernels as virtual machines. Previously, researchers had only been able to run up to 20,000 kernels concurrently. The scientists used virtual machine (VM) technology and its Thunderbird supercomputing cluster for [...]]]></description>
				<content:encoded><![CDATA[<p>In a feat of Linux strength, computer scientists at Sandia National Laboratories in Livermore, Calif., announced that they had run more than <a href="http://www.sandia.gov/news/resources/releases/2009/linux.html">a million Linux kernels as virtual machines</a>. Previously, researchers had only been able to run up to 20,000 kernels concurrently. The scientists used virtual machine (VM) technology and its Thunderbird supercomputing cluster for the demonstration.</p>
<p>The aim of the project is to model malicious botnets, which are often difficult to analyze because they are geographically spread all over the world, explains Sandia&#8217;s Ron Minnich. The more kernels that can be run at once, said Minnich, the more effective cyber security professionals can be in combating the global botnet problem. “Eventually, we would like to be able to emulate the computer network of a small nation, or even one as large as the United States, in order to virtualize and monitor a cyber attack,” he said.</p>
<p>Running a high volume of VMs on one supercomputer — at a similar scale as a botnet — would allow researchers to see how botnets work and explore ways to stop them in their tracks. “We can get control at a level we never had before,” said Minnich.<br />
<span id="more-767"></span><br />
A related use for millions to tens of millions of operating systems, Sandia’s researchers suggest, is to construct high-fidelity models of parts of the Internet.</p>
<p>“The sheer size of the Internet makes it very difficult to understand in even a limited way,” said Minnich. “Many phenomena occurring on the Internet are poorly understood, because we lack the ability to model it adequately. By running actual operating system instances to represent nodes on the Internet, we will be able not just to simulate the functioning of the Internet at the network level, but to emulate Internet functionality.”</p>
<p>To complete the project, Sandia utilized its Albuquerque-based 4,480-node Dell high-performance computer cluster, known as <a href="http://www.sandia.gov/news/resources/releases/2006/thunderbird.html">Thunderbird</a>. To arrive at the one million Linux kernel figure, Sandia’s researchers ran one kernel in each of 250 VMs and coupled those with the 4,480 physical machines on Thunderbird. Dell and IBM both made key technical contributions to the experiments, as did a team at Sandia’s Albuquerque site that maintains Thunderbird and prepared it for the project.</p>
<p>The capability to run a high number of operating system instances inside of virtual machines on a high performance computing (HPC) cluster can also be used to model even larger HPC machines with millions to tens of millions of nodes that will be developed in the future, said Minnich. This successful demonstration, he asserts, means that development of operating systems, configuration and management tools, and even software for scientific computation can start before the hardware technology is mature.</p>
<p>“Development of this software will take years, and the scientific community cannot afford to wait to begin the process until the hardware is ready,” said Minnich. “Urgent problems such as modeling climate change, developing new medicines, and research into more efficient production of energy demand ever-increasing computational resources. Furthermore, virtualization will play an increasingly important role in the deployment of large-scale systems, enabling multiple operating systems on a single platform and application-specific operating systems.”</p>
<p>Sandia’s researchers plan to take their newfound capability to the next level.</p>
<p>“It has been estimated that we will need 100 million CPUs (central processing units) by 2018 in order to build a computer that will run at the speeds we want,” said Minnich. “This approach we’ve demonstrated is a good way to get us started on finding ways to program a machine with that many CPUs.” Continued research, he said, will help computer scientists to come up with ways to manage and control such vast quantities, “so that when we have a computer with 100 million CPUs we can actually use it.”</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/enterprise-linux/researchers-boot-one-million-linux-kernels-as-virtual-machines/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Centrify streamlines administrator tasks in mixed environments</title>
		<link>http://itknowledgeexchange.techtarget.com/enterprise-linux/centrify-streamlines-administrator-tasks-in-mixed-environments/</link>
		<comments>http://itknowledgeexchange.techtarget.com/enterprise-linux/centrify-streamlines-administrator-tasks-in-mixed-environments/#comments</comments>
		<pubDate>Wed, 29 Oct 2008 20:31:19 +0000</pubDate>
		<dc:creator>Suzanne Wheeler</dc:creator>
				<category><![CDATA[Administration, interoperability and integration]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[Data center physical infrastructure]]></category>
		<category><![CDATA[Enterprise applications for Linux]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/enterprise-linux/centrify-streamlines-administrator-tasks-in-mixed-environments/</guid>
		<description><![CDATA[On Oct. 21, Mountain View, Calif.based Centrify Corp. added DirectAuthorize to its suite of products for integrating Active Directory into mixed Linux and Windows environments. DirectAuthorize streamlines user access rights management so that administrators no longer have to configure rights separately on Windows servers and then on non-Windows servers. By consolidating information in a centralized [...]]]></description>
				<content:encoded><![CDATA[<p><span><font face="Arial">On Oct. 21, Mountain View, Calif.based </font><a href="http://www.centrify.com/"><font face="Arial">Centrify Corp.</font></a><font face="Arial"> added </font><a href="http://www.centrify.com/directauthorize/unix-privilege-management.asp"><font face="Arial">DirectAuthorize</font></a><font face="Arial"> to its suite of products for integrating </font><a href="http://www.microsoft.com/windowsserver2003/technologies/directory/activedirectory/default.mspx"><font face="Arial">Active Directory</font></a><font face="Arial"> into mixed Linux and Windows environments. DirectAuthorize streamlines user access rights management so that administrators no longer have to configure rights separately on Windows servers and then on non-Windows servers. By consolidating information in a centralized location, DirectAuthorize eliminates redundant rework.</font></span><span><font face="Arial"> </font></span><span> </span><span></span><span><font face="Arial"> </font></span></p>
<p><span><font face="Arial">DirectAuthorize arrives as the third member of a line of products created to ease the task of managing mixed environments with Active Directory. The other two products, DirectControl and DirectAudit, perform centralized authentication and auditing. </font></span><span><font face="Arial"> </font></span><span><span> </span></span><span><span></span></span><span><span></span></span><span><span></span></span><span><span></span></span><span><span></span></span><span><span></p>
<p class="MsoNormal"><span><font face="Arial">“Typically we serve customers who are looking to introduce Linux, Hewlett-Packard, AIX, or Unix into their environments, and also often VMware.” Centrify CEO Tom Kemp said. “In terms of access rights and password management, that ends up being a lot of sticky notes next to your screen.” DirectAuthorize replaces non-Windows systems’ authorization infrastructure with that of Active Directory, which allows admins to move all user authorization information to a central location and to manage it from that location.</font></span></p>
<p></span></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/enterprise-linux/centrify-streamlines-administrator-tasks-in-mixed-environments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SE-Postgres tightens SQL security</title>
		<link>http://itknowledgeexchange.techtarget.com/enterprise-linux/se-postgres-tightens-sql-security/</link>
		<comments>http://itknowledgeexchange.techtarget.com/enterprise-linux/se-postgres-tightens-sql-security/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 19:33:30 +0000</pubDate>
		<dc:creator>Suzanne Wheeler</dc:creator>
				<category><![CDATA[Administration, interoperability and integration]]></category>
		<category><![CDATA[DataManagement]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[PostGreSQL]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/enterprise-linux/se-postgres-tightens-sql-security/</guid>
		<description><![CDATA[This post was contributed by Joshua Kramer. For more information about Kramer, go to the EnterpriseLinuxLog About the Editors page. In the theater of IT operations, security has moved to center stage. Attacks have become more complex, and legislative bodies have passed laws that require data protection. In just the past year, Nevada and Massachusetts introduced legislation requiring that consumer [...]]]></description>
				<content:encoded><![CDATA[<p class="MsoNormal"><span><em>This post was contributed by Joshua Kramer.</em> <em>For more information about Kramer, go to the EnterpriseLinuxLog <a href="http://itknowledgeexchange.techtarget.com/enterprise-linux/about" title="Bio page">About the Editors</a> page. </em></span></p>
<p class="MsoNormal"><span></span></p>
<p><span>In the theater of IT operations, security has moved to center stage. Attacks have become more complex, and legislative bodies have passed laws that require data protection. In just the past year, Nevada and Massachusetts introduced legislation requiring that consumer data be protected.</span><span> </span></p>
<p><span></span><span><span> </span></span><span><span></span></span><span></span><span><span>In 2006, Oracle introduced its <a href="http://www.oracle.com/technology/products/audit-vault/index.html"><span>Audit Vault</span><span><span></span></span></a>, which purported to restrict access to data even from database management administrators. This kind of tool is extremely valuable in the fight against those trying to steal personal information.<span> </span><span> <span><span> </span></span></span></span></span></p>
<p><span><span><span><span><span>In early 2009, another player will offer a similar &#8212; and perhaps more secure &#8212; way to restrict data access As part of its yearly feature update, the <a href="http://www.postgresql.org/" target="_blank">PostgreSQL</a> group plans to implement a module called SE-Postgres in the database core. This module inherits security rules and contexts from the SELinux rule set of the host OS to control access to tables, individual rows of data and even individual columns. Currently SE-Postgres is available as a patch to the Postgres 8.3 database (for those who don&#8217;t mind compiling source code).</span><span> </span><span><span> </span></span></span></span></span></span></p>
<p><span><span><span><span><span><span></span></span></span></span></span></span><span></span><span><span><span><span><span><span></span></span></span></span></span><span><span><span><span><span>This inheritance of rules applies to all facets of SELinux and therefore gives you power beyond simply restricting access by role. When SE-Postgres is configured properly, a client&#8217;s SELinux context is propagated to all data it touches. For example, rows inserted by a subject with SystemHigh privileges will carry the Secret label. A query submitted by a subject with user_t privileges will not return rows that have such a label. For the most part, referential integrity is preserved; a table join will fail if one of the objects required in a table is disallowed by SELinux context. There are a few minor exceptions, but those will be closed as the project progresses.</span></span></span></span></span></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/enterprise-linux/se-postgres-tightens-sql-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Whirlwind Tech Tour explores remote administration tools</title>
		<link>http://itknowledgeexchange.techtarget.com/enterprise-linux/whirlwind-tech-tour-explores-remote-administration-tools/</link>
		<comments>http://itknowledgeexchange.techtarget.com/enterprise-linux/whirlwind-tech-tour-explores-remote-administration-tools/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 19:19:06 +0000</pubDate>
		<dc:creator>Suzanne Wheeler</dc:creator>
				<category><![CDATA[Administration, interoperability and integration]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[Enterprise applications for Linux]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/enterprise-linux/whirlwind-tech-tour-explores-remote-administration-tools/</guid>
		<description><![CDATA[This week, SearchEnterpriseLinux.com launched its Whirlwind Tech Tour, a new site feature in which we ask Linux professionals a weekly question and post their answers side by side. This week we asked about remote server administration. Done correctly, remote server administration enables companies to distribute resources and prepare for disaster recovery. It also requires a [...]]]></description>
				<content:encoded><![CDATA[<p><span>This week, <a href="http://searchenterpriselinux.techtarget.com/news/article/0,289142,sid39_gci1335409,00.html">SearchEnterpriseLinux.<span>com</span></a></span><span> launched its Whirlwind Tech Tour, a new site feature in which we ask Linux professionals a weekly question and post their answers side by side</span><span>. This week we asked about remote server administration. Done correctly, remote server administration enables companies to distribute resources and prepare for disaster recovery. It also requires a strong toolset</span><span> to perform these roles well. </span><span> </span></p>
<p><span></span><span><strong><span>Which tool is best for remote server administration in a Linux environment, and why</span></strong><strong><span>?</span></strong></span></p>
<p><span><strong><span> </span></strong><span></span><span>Jay Lyman, an open source analyst at Boulder, Colo.-based <a href="http://www.451group.com/"><font color="#800080">451 Group</font></a>, recommends the General Public License-licensed Virtual Network Computing (VNC) system for its user-friendly general user interface</span><span>. This tool <a target="_blank" href="http://searchenterpriselinux.techtarget.com/generic/0,295582,sid39_gci1334161,00.html"><span><font color="#800080">works with Open Secure Shell (OpenSSH) to perform tunneling</font></span></a></span><span>, a method to establish secure connections between local and remote networks. </span><span> </span></span><span><span>OpenSSH itself received several mentions in our IT pros’ responses</span><span class="MsoCommentReference"><span><span><font face="Times New Roman"> </font></span></span></span><span>. </span></span></p>
<p><span><span>As Kristian Erik Hermansen noted, the tool does more than tunnel. Hermansen’s description of OpenSSH’s capabilities: It can “forward graphical applications to remote machines, create a series of tunnels, redirect traffic over a SOCKS</span><span> proxy, and perform way too many other features to mention.” </span><span> </span></span></p>
<p><span><span></span><span><span>Serge Wroclawski expected SSH to be at the top of respondents’ lists but suggested they trade it in for more automated remote administration tools. He advises managing remote server configuration with tools such as <a target="_blank" href="http://trac.mcs.anl.gov/projects/bcfg2"><font color="#800080">bcfg2</font></a> and <a href="http://reductivelabs.com/projects/puppet/"><font color="#800080">Puppet</font></a>.</span><span> </span></span></span></p>
<p><span><span>“Remote server management is a multidimensional problem, and managing the Linux OS is only a part of it,” said <a href="http://www.ideasinternational.com/"><font color="#800080">Ideas <span>International</span></font></a> Inc. </span></span></p>
<p><span><span>CEO Tony Iams Iams outlined several considerations in approaching this problem, but concluded that</span><span class="MsoCommentReference"><span><span><font face="Times New Roman"> </font></span></span></span><span> “perhaps the most important factor in choosing a remote Linux management tool…is to make sure it integrates smoothly into the dominant management tools and procedures that are already in place.”</span><span> </span></span></p>
<p><span><span></span><span><span>Do you have a question you’d like to see asked and answered? Email it to editor@searchenterpriselinux.com</span><span class="MsoCommentReference"><span><span><font face="Times New Roman"> </font></span></span></span><span>.</span><font face="Times New Roman"> </font></span><span><span>To see the complete responses from our IT pros, go to the </span><span><a target="_blank" href="http://searchenterpriselinux.techtarget.com/generic/0,295582,sid39_gci1335959,00.html">feature main page</a>.</span></span></span></p>
<hr SIZE="1" width="33%" align="left" class="msocomoff" />
<p class="msocomtxt"><span><a name="_msocom_1" title="_msocom_1"></a></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/enterprise-linux/whirlwind-tech-tour-explores-remote-administration-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trusted Computer Solutions shores up security methods with CounterStorm</title>
		<link>http://itknowledgeexchange.techtarget.com/enterprise-linux/trusted-computer-solutions-shores-up-security-methods-with-counterstorm/</link>
		<comments>http://itknowledgeexchange.techtarget.com/enterprise-linux/trusted-computer-solutions-shores-up-security-methods-with-counterstorm/#comments</comments>
		<pubDate>Tue, 07 Oct 2008 15:53:31 +0000</pubDate>
		<dc:creator>Suzanne Wheeler</dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[Enterprise applications for Linux]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/enterprise-linux/trusted-computer-solutions-shores-up-security-methods-with-counterstorm/</guid>
		<description><![CDATA[As threats become less predictable and more targeted, security technologies have shored up their methods and devised additional precautions to secure company systems. With its acquisition of CounterStorm, a government-run security software company, Trusted Computer Solutions (TCS) has done just that. CounterStorm adds to TCS’ existing security protection process built into TCS’ Security Blanket. Security [...]]]></description>
				<content:encoded><![CDATA[<p>As threats become less predictable and more targeted, security technologies have shored up their methods and devised additional precautions to secure company systems. With its acquisition of <a target="”_blank”" href="”http://www.counterstorm.com”">CounterStorm</a>, a government-run security software company, <a target="”_blank”" href="”http://www.tcs-sec.com/”">Trusted Computer Solutions (TCS)</a> has done just that. CounterStorm adds to TCS’ existing security protection process built into TCS’ <a target="”_blank”" href="”">Security Blanket</a>. Security Blanket hardens and creates a baseline for a system, and CounterStorm acts as a vigilant guard to maintain these measures.</p>
<p>“Ten years ago, most attacks were random,” said Ed Hammersla, the chief operating officer at TCS. “Now we are seeing attackers who have a focused knowledge of their victims. CounterStorm acts as a last line of defense in an environment in which more serious, targeted attacks … have become prevalent.”</p>
<p>Security Blanket first runs a security compliance profile on a system, automatically brings it into compliance with specified security standards and monitors the system for possible breaches.</p>
<p>CounterStorm strengthens the lockdown process with yet another measure: anomaly-based targeted threat prevention that observes a system’s typical behavior, scans for deviations and isolates and attacks these anomalies. With this approach to abnormalities, CounterStorm makes server scanning and issue resolution easier for admins. “It is much easier and less costly to fix 100 servers than it is to fix 1,000,” said Hammersla.</p>
<p>With the acquisition, TCS expands further into commercial applications for its security tools. Hammerla said that while government and the private sector have different security needs, an unsecured system can result in damage to either. “Government and commercial software security administrators have different concerns,” Hammersla said, “but face the same consequences.”</p>
<p>“Hospitals, for example, are not particularly anxious about their networks being infiltrated by China, but the government certainly is,” Hammersla said. “However, over time, I think that we will see more and more of the commercial and government compliancy standards merging.”</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/enterprise-linux/trusted-computer-solutions-shores-up-security-methods-with-counterstorm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sourcefire strengthens virtualization security with RNA</title>
		<link>http://itknowledgeexchange.techtarget.com/enterprise-linux/sourcefire-strengthens-virtualization-security-with-rna/</link>
		<comments>http://itknowledgeexchange.techtarget.com/enterprise-linux/sourcefire-strengthens-virtualization-security-with-rna/#comments</comments>
		<pubDate>Tue, 16 Sep 2008 19:06:08 +0000</pubDate>
		<dc:creator>Suzanne Wheeler</dc:creator>
				<category><![CDATA[Hardware issues]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/enterprise-linux/sourcefire-strengthens-virtualization-security-with-rna/</guid>
		<description><![CDATA[As attacks upon software systems become more sophisticated, it is crucial to adapt security measures to emerging threats. Virtualization is presently one of the most exciting technologies in the enterprise, but also among the most vulnerable. At VMworld, Sourcefire, the security company that brought Snort to the market, has introduced a new product offering through [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&amp;gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&amp;gt;     --><!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:#383A3B; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} span.ccbntxt 	{mso-style-name:ccbntxt;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --><!--[if gte mso 10]&amp;gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p class="MsoNormal"> <!--[if gte mso 9]&amp;gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&amp;gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} p 	{mso-margin-top-alt:auto; 	margin-right:0in; 	mso-margin-bottom-alt:auto; 	margin-left:0in; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&amp;gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p>As attacks upon software systems become more sophisticated, it is crucial to adapt security measures to emerging threats. Virtualization is presently one of the most exciting technologies in the enterprise, but also among the most vulnerable.</p>
<p class="MsoNormal"><span class="ccbntxt"><span>At </span></span><span><a href="http://searchservervirtualization.techtarget.com/generic/0,295582,sid94_gci1330263,00.html" target="_blank">VMworld</a>, <span class="ccbntxt"><a href="www.sourcefire.com" target="_blank">Sourcefire</a>, the security company that brought Snort to the market, has introduced a new product offering through its <a href="http://www.sourcefire.com/products/3D" target="_blank">Sourcefire 3D</a></span>. Most important, the release improves <span class="ccbntxt">Real-time Network Awareness (RNA), a feature able to monitor both hardware and virtual environments.</span></span></p>
<p class="MsoNormal"><span class="ccbntxt"><span>First, RNA enables administrators to tailor the software to their compliance and policy requirements; the VM Detection feature combats the problem of VM sprawl by detecting all virtual machines and making them visible.</span></span></p>
<p class="MsoNormal"><span class="ccbntxt"><span>RNA is now supported by VMware’s support services, <a href="http://www.vmware.com/partners/alliances/programs/" target="_blank">Technology Alliance Partner (TAP)</a> program and VMsafe. VMsafe includes an <a href="http://rationalsecurity.typepad.com/blog/2008/02/vmwares-vmsafe.html" target="_blank">application program interface (API)</a>, which enables other security applications to monitor for and catch intrusions that RNA cannot see.</span></span></p>
<p class="MsoNormal"><span class="ccbntxt"><span>RNA saves enterprise resources by identifying threats as they occur by continuously collecting information about virtual machine activity at the surface level of a virtual environment. Other security tools collect such data only during the day, allowing intruders greater opportunity to inflict harm on the system. </span></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/enterprise-linux/sourcefire-strengthens-virtualization-security-with-rna/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SELinux now enabled in AppArmor&#8217;s openSUSE</title>
		<link>http://itknowledgeexchange.techtarget.com/enterprise-linux/selinux-now-enabled-in-apparmor-territory-opensuse/</link>
		<comments>http://itknowledgeexchange.techtarget.com/enterprise-linux/selinux-now-enabled-in-apparmor-territory-opensuse/#comments</comments>
		<pubDate>Tue, 02 Sep 2008 14:19:04 +0000</pubDate>
		<dc:creator>Suzanne Wheeler</dc:creator>
				<category><![CDATA[Administration, interoperability and integration]]></category>
		<category><![CDATA[Enterprise applications for Linux]]></category>
		<category><![CDATA[Interviews]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Open source applications]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SELinux]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/enterprise-linux/selinux-now-enabled-in-apparmor-territory-opensuse/</guid>
		<description><![CDATA[On Friday, Aug. 22, openSUSE announced that its newest version, 11.1, will support Security Enhanced Linux, or SELinux. Novell’s security tools, AppArmor and SELinux, have traditionally been considered intense rivals. In this interview, openSUSE’s Andreas Jaeger, Roman Drahtmüller and Matthias Eckermann discuss openSUSE’s support of SELinux. OpenSUSE now has basic enablement with SELinux. That’s great [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&amp;gt;     Normal   0         false   false   false                             MicrosoftInternetExplorer4   --><!--[if gte mso 9]&amp;gt;     --> <!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{color:purple; 	text-decoration:underline; 	text-underline:single;} p 	{mso-margin-top-alt:auto; 	margin-right:0in; 	mso-margin-bottom-alt:auto; 	margin-left:0in; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&amp;gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;}  --></p>
<p><em><span>On Friday, Aug. 22, <a href="”http://www.opensuse.org/”">openSUSE</a> announced that its newest version, 11.1, will support <a href="”">Security Enhanced Linux, or SELinux</a>. Novell’s security tools, <a href="”http://searchenterpriselinux.techtarget.com/tip/0,289483,sid39_gci1281393,00.html”">AppArmor and SELinux</a>, have traditionally been considered intense rivals. In this interview, openSUSE’s Andreas Jaeger, Roman Drahtmüller and Matthias Eckermann discuss openSUSE’s support of SELinux.</span></em></p>
<p><strong><span>OpenSUSE now has <a href="”http://lwn.net/Articles/294994/“">basic enablement</a> with SELinux. That’s great for SELinux users now, but will openSUSE be able to integrate new patches for SELinux?</span></strong><span></span></p>
<p><strong><span>Andreas Jaeger :</span></strong><span> OpenSUSE is developed with a community approach; We are proud to have opened the <a href="”https://build.opensuse.org/“">openSUSE build service</a> to the community, with the option to develop and package open source software cross-distribution.</span></p>
<p><span>As SELinux is a cross-distribution effort, we encourage members of the SELinux community to participate in the openSUSE build service: to develop, test-drive and integrate new user land patches and tools into openSUSE and other distributions using our cross-distribution service. This way, all distributions running with SELinux enabled in the Linux kernel will benefit.</span></p>
<p><strong><span>Is support of SELinux indicative of a larger industry trend toward interoperability?</span></strong><span></span></p>
<p><strong><span>Roman Drahtmüller:</span></strong><span> Novell observes a tendency in the industry to increase the security value of a system by introducing additional controls beyond the scope of the application. This means the application is exposed to these controls but cannot change them.</span></p>
<p><strong><span>In moving from AppArmor to SELinux, does a company sacrifice compliance benefits?</span></strong><span></span><strong><span></span></strong></p>
<p><strong><span>Drahtmüller: </span></strong><span>AppArmor profiles for application containment and confinement are comparatively easy to manage throughout an infrastructure. Creating them is a distinct, low-pain checkmark item. The same applies to evaluating log messages that record possible violation attempts against protected system services.</span></p>
<p><span>For customers, the transition to SELinux may need a change in thinking and architecture, but also allows for the definition of a complete policy in a system. It helps to disallow actions that are not subject to a defined policy. There are environments that require such a functionality &#8212; regardless of the cost associated with it &#8212; for compliance reasons.</span></p>
<p><span>We anticipate that customers with these requirements will aim for a SUSE Linux Enterprise operating system, as it targets the special needs of customers working in compliance-bound environments.</span></p>
<p><strong><span>Security tools have created a tradeoff between capability (SELinux) and usability (AppArmor). Is Novell’s approach to this tradeoff changing with its basic enablement of SELinux?</span></strong><span></span></p>
<p><strong><span>Matthias Eckermann: </span></strong><span>As in earlier releases of our product, openSUSE 11.1 reflects our belief in the value of additional security mechanisms in the operating system. The benefit of such mechanisms is maximized if the configuration and administration is as transparent, straightforward and as easy as possible for administrators.</span></p>
<p><span>Security needs that aim toward <a href="”http://searchenterpriselinux.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid39_gci1326898,00.html”">mandatory access control</a>, <a href="”">mandatory integrity control</a> or even <a href="”">multi-level security</a> require a suitable architecture. With the basic SELinux enablement, we will allow our partners and customers to use such an architecture to implement solutions that fulfill their specific needs.</span></p>
<p><span>Nevertheless, we want our users to be able to choose their own priorities between administrative effort and functional benefit.</span></p>
<p><em><span>What do you think? Leave a comment below or contact <a href="mailto:chunter@techtarget.com">chunter@techtarget.com</a>.</span></em><span></span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span> </span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/enterprise-linux/selinux-now-enabled-in-apparmor-territory-opensuse/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Red Hat tight-lipped on breach, but risk appears small</title>
		<link>http://itknowledgeexchange.techtarget.com/enterprise-linux/red-hat-tight-lipped-on-breach-but-risk-appears-small/</link>
		<comments>http://itknowledgeexchange.techtarget.com/enterprise-linux/red-hat-tight-lipped-on-breach-but-risk-appears-small/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 20:21:14 +0000</pubDate>
		<dc:creator>Dkr</dc:creator>
				<category><![CDATA[authentication]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Open source applications]]></category>
		<category><![CDATA[Red Hat]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[TechTarget Blogs]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/enterprise-linux/red-hat-tight-lipped-on-breach-but-risk-appears-small/</guid>
		<description><![CDATA[Red Hat Inc. has declined to provide additional details on last week’s security breach on some Fedora servers that were illegally accessed. Although Red Hat said it did not believe that the package-signing key used to gain access to Fedora operating systems was compromised, the Raleigh, N.C.-based company issued a new Fedora signing key as [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.redhat.com" target="_blank">Red Hat Inc.</a> has declined to provide additional details on last week’s security breach on some <a href="http://www.fedora.com" target="_blank">Fedora</a> servers that were illegally accessed. Although Red Hat said it did not believe that the package-signing key used to gain access to Fedora operating systems was compromised, the Raleigh, N.C.-based company issued a new Fedora signing key as a precaution. Fedora is Red Hat’s free operating system where innovations are introduced and tested before they are incorporated into production-ready Red Hat Enterprise Linux (RHEL).</p>
<p>Related to the Fedora intrusion, Red Hat also announced a breach into a few Open Secure Shell (SSH) security encryption packages for some versions of RHEL 4 and RHEL 5 that are not under the umbrella of a Red Hat network management system. As a precaution, Red Hat issued an updated version of the affected RHEL Open SSH security packages.</p>
<p><strong>No big deal? </strong><br />
Reaction to the breach is muted at best.</p>
<p>Joe Clabby, a principal at Falmouth, Maine-based <a href="http://www.clabbyanalytics.com" target="_blank">Clabby Analytics</a>, said that a new signing key install “could be a real hassle” for a large install base without an automated deployment system, but he didn’t think it was a huge problem. “It’s good they found it and made it public so people can fix it and life goes on,” he said.</p>
<p>Charles King, a principal analyst at Hayward, Calif.-based <a href="http://www.pund-it.com">Pund-IT Inc.</a>, agreed.</p>
<p>A security breach is “always disquieting,” he noted, but this one is probably of lesser impact, because most data centers do not run Red Hat exclusively. In one sense, the breach could be viewed as an indicator of Red Hat’s growing success. Hackers generally target only commercially successful distros, King said.</p>
<p>Well-known tech blogger Jason Perlow said that the breach is “standard stuff” that will be remedied quickly because the entire open source community will become engaged in developing a remedy, versus a breach with a proprietary vendor, which could take months to solve the problem.</p>
<p>I suspect that most large Red Hat installs run RHEL rather than Fedora, thus reducing the probable risk to businesses. Nevertheless, as an admittedly impatient journalist wired to ask questions and expect answers, Red Hat’s failure to be more forthcoming about the extent of the breach and the potential impact is disappointing. Users aren&#8217;t well served by a limited statement and a wall of silence.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/enterprise-linux/red-hat-tight-lipped-on-breach-but-risk-appears-small/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco router too costly? Vyatta wants to help</title>
		<link>http://itknowledgeexchange.techtarget.com/enterprise-linux/vyattas-bigger-router-appliance-targets-the-enterprise/</link>
		<comments>http://itknowledgeexchange.techtarget.com/enterprise-linux/vyattas-bigger-router-appliance-targets-the-enterprise/#comments</comments>
		<pubDate>Thu, 14 Aug 2008 18:07:34 +0000</pubDate>
		<dc:creator>Dkr</dc:creator>
				<category><![CDATA[Hardware issues]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Open source applications]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[TechTarget Blogs]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/enterprise-linux/vyattas-bigger-router-appliance-targets-the-enterprise/</guid>
		<description><![CDATA[Vyatta Inc., the startup with attitude vying to take on the mighty Cisco Systems Inc., is seeking to expand its toehold in the networking market with the introduction of a larger router and security networking appliance &#8212; and at a fraction of the cost of comparable Cisco gear. The Belmont, Calif., company, which describes its [...]]]></description>
				<content:encoded><![CDATA[<p class="MsoNormal"><font face="Arial" size="2"><span><a href="http://www.vyatta.com/" title="http://www.vyatta.com Vyatta Inc." target="_blank">Vyatta Inc</a>., the startup with attitude vying to take on the mighty <a href="http://www.cisco.com" title="http://www.cisco.com Cisco Systems Inc.">Cisco Systems  Inc</a>., is seeking to expand its toehold in the networking market with the introduction of a larger router and security networking appliance &#8212; and at a fraction of the cost of comparable Cisco gear. </span></font></p>
<p><font face="Arial" size="2"><span>The  Belmont, Calif., company, which describes its customers as smarter and better looking than those of its giant competitor in its press  releases, debuted its 2501 appliance last week at LinuxWorld Conference &amp; Expo. The 2501 has nearly twice the horsepower (1.8 GHz versus 1 GHz) and more expansion slots than its 514 predecessor, which was introduced last March.</span></font></p>
<p><font face="Arial" size="2"><span>Although Cisco has overwhelming market share, Vyatta’s pitch is its eye-popping price advantage (it’s about a tenth of Cisco’s cost). In addition, the functionality of Vyatta’s router is in software, which is easy to upgrade, versus Cisco’s proprietary hardware boxes, which can only be upgraded via replacement.</span></font></p>
<p><font face="Arial" size="2"><span>Rob  Whiteley, the principal analyst at <a href="http://www.forrester.com" title="http://www.forrester.com Forrester Research Inc.">Forrester  Research Inc.</a> in Cambridge, Mass., said the new router is better and more powerful than its predecessor and would enable Vyatta to go after  more than the low-hanging fruit of small companies and branch  offices.</span></font></p>
<p class="MsoNormal"><font face="Arial" size="2"><span>The 2501, in contrast,  has the additional processing power and throughput required for medium to large  networks and could function as a link to a wide area network (WAN) or a security  appliance. </span></font></p>
<p><font face="Arial" size="2"><span>Vyatta will never be large enough to meet all of most companies’ needs, Whiteley said. But the growing acceptance of  open source products and the current budget-shrinking economy should help Vyatta&#8217;s cause, he said. Ultimately, Vyatta’s success will depend on its ability to offer additional services along with its routers, he  said.</span></font></p>
<p class="MsoNormal"><font face="Arial" size="2"><span> </span></font></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/enterprise-linux/vyattas-bigger-router-appliance-targets-the-enterprise/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Surveillance tools beat hidden malware at its own game</title>
		<link>http://itknowledgeexchange.techtarget.com/enterprise-linux/surveillance-tools-beat-hidden-malware-at-its-own-game/</link>
		<comments>http://itknowledgeexchange.techtarget.com/enterprise-linux/surveillance-tools-beat-hidden-malware-at-its-own-game/#comments</comments>
		<pubDate>Thu, 14 Aug 2008 13:53:07 +0000</pubDate>
		<dc:creator>Suzanne Wheeler</dc:creator>
				<category><![CDATA[Administration, interoperability and integration]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Systems Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/enterprise-linux/surveillance-tools-beat-hidden-malware-at-its-own-game/</guid>
		<description><![CDATA[Just as surveillance tools have flourished in the physical world because they can monitor systems in hiding – think nanny cam – such seemingly invisible monitoring systems have flourished in the digital domain. Rootkits, a form of malware designed to take control of a system without the authorization or knowledge of an administrator, can wreak [...]]]></description>
				<content:encoded><![CDATA[<p>Just as surveillance tools have flourished in the physical world because they can monitor systems in hiding – think nanny cam – such seemingly invisible monitoring systems have flourished in the digital domain. </p>
<p>Rootkits, a form of malware designed to take control of a system without the authorization or knowledge of an administrator, can wreak havoc on a system and compromise everything it does by infecting code, nestling within it and becoming the malevolent phantom of an OS.</p>
<p>If security plays second fiddle to other system administration duties, your system may be just as much at risk as if you didn’t monitor it at all. But a new crop of rootkit detection tools is designed to detect these malware breaches and, in some cases, beat malware at its own game.</p>
<p>Products such as <a href="http://www.f-secure.com/blacklight/”" target="_blank”">F-Secure Blacklight</a> and <a href="”http://www.ossec.net/”" target="”_blank”">OSSEC</a> help protect system information from being used against you by making it inaccessible to nonadministrators. Unlike traditional antivirus scanners, these tools examine the system at a deep level to detect active rootkits and rout them out. Tools like Blacklight also tout themselves as user-friendly and nontechnical .</p>
<p>The new security tool <a href="”http://www.linuxsecurity.com/content/view/141042/169/”" target="”_blank”">ProcL</a> goes a step further by hiding information about which version of software a system uses. As a result, malware attempting to gain system access cannot tell whether the system has software from 2008 or 1988 and will likely move on to an easier target. </p>
<p></a>For more on ProcL, <a href="”http://www.scanit.net/rd/tools/03”" target="”_blank”">see the Scanit website</a>. And to check out an advanced security “hiding” tactic involving virtualization, click <a href="”http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1322172,00.html”" target="”_blank”">here</a>. </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/enterprise-linux/surveillance-tools-beat-hidden-malware-at-its-own-game/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
