Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Servers

    Linux Vendors Increase Security Features

    Written by

    Jason Brooks
    Published October 14, 2008
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Linux-based operating systems are built on an open-development model, which can afford organizations an early view of-and an opportunity to influence-the technologies and implementations that will eventually work their way into these companies’ infrastructures.

      What’s more, these early looks extend beyond points on a presentation slide to comprise run-able code that’s gathered into fast-moving, community-supported Linux distributions that administrators can begin testing in advance of the long-lived, enterprise-oriented releases to come.

      I examined the principal security-related developments in three such vanguard Linux distributions, Canonical’s Ubuntu Linux 8.10, Novell’s OpenSUSE 11.1 and Red Hat’s Fedora 10, all of which are now available in beta form.

      Ubuntu Linux 8.10, which is slated for release at the end of October, ships with an encrypted private directory feature that enables users to store sensitive data securely without incurring the performance overhead of full-volume encryption.

      Click here to read about Microsoft’s October patches and its new Exploitability Index.

      In my own tests with full-volume encryption in previous Ubuntu versions, I’ve noted processor overhead of about 20 to 30 percent during disk-intensive processes such as virtual machine image creation.

      What’s more, full-disk encryption, unlocked by a single pass key, poses problems for multiuser machines, in which the disk unlocking is an all-or-nothing proposition, as opposed to a user-by-user measure.

      As implemented in Ubuntu 8.10, the encrypted private directory feature creates a folder-labeled “Private”-in users’ home directories. The system automatically encrypts files placed in this directory and unlocks the directory upon user log-on.

      In my tests, I could broaden the range of home directory folders that the system protected by copying the folders to the Private location and leaving a symlink behind to allow my applications to continue accessing the protected files at their previous addresses.

      As this feature now stands, it’s too roughly implemented to supplant full-volume encryption entirely-there’s no user interface at this point, and there’s the possibility that sensitive data could be pulled from a system’s unencrypted swap partition. I hope to see Ubuntu’s encryption feature set firmed up to include full-volume, Private folder and home directory encryption in time for the distribution’s next LTS (Long Term Support) release, which is currently scheduled for April 2010.

      Access Control and Audit Tools

      Version 11.1 of Novell’s OpenSUSE, which is the community-oriented sibling of the company’s more buttoned-down SUSE Linux Enterprise distributions, is slated for release at the beginning of December, complete with basic support for the SELinux mandatory access control system.

      Novell’s embrace of SELinux has raised eyebrows in the Linux community because SELinux has been primarily a Red Hat-driven initiative over the past few years. For its part, Novell has been pushing an alternative access control scheme, called AppArmor, which was the fruit of Novell’s 2005 acquisition of Immunix.

      Novell has often called out Red Hat and SELinux for the system’s complexity-a Linux system secured with SELinux carries policies that closely govern the specific actions and rights of every user, file and application on a machine, and these policies can be very difficult to create, review and troubleshoot.

      However, as implemented by Red Hat, SELinux can be enabled with a targeted policy that tightly controls certain applications while leaving others to the supervision of traditional Linux access controls.

      OpenSUSE 11.1 will ship with only basic support for SELinux-AppArmor remains the suggested security enhancement mechanism for the distributions-but according to Novell, the addition of basic SELinux support will allow customers who have adopted SELinux to migrate their systems to Novell’s Linux operating system.

      Click here to read Security Center Editor Larry Seltzer’s comparison of vulnerability ratings systems.

      Version 10 of Red Hat’s Fedora Linux distribution, which is scheduled for release at the end of November, is set to ship with a new security audit and intrusion prevention tool.

      Between this new tool, Fedora’s support for full-volume encryption at install time (a feature that Ubuntu also offers but OpenSUSE lacks) and Fedora’s well-implemented SELinux subsystem, Red Hat has delivered the most well-rounded complement of security features available on any current Linux distribution.

      The new audit utility, which Red Hat is calling Sectool, provides a set of system tests for detecting configuration issues regarding permissions, firewall rules and the status of other system security features. In addition, Sectool offers administrators a framework for writing their own tests in Bash, Python or other scripting languages.

      As implemented in Fedora 10, Sectool organizes sets of tests into five security levels, with ascending security strictness: Naive, Desktop, Network, Server or Paranoid.

      I ran the graphical version of the Sectool utility (there’s also a command-line version) on a Fedora 10 beta installation at a few of the security levels, and the tool responded with errors, problems that I should fix and warnings, or less serious informational messages.

      The tool offered enough information in the error messages to point me in the right direction toward resolving the issues, but this functionality could be better integrated with the system’s configuration tools.

      eWEEK Labs Executive Editor Jason Brooks can be reached at [email protected].

      Jason Brooks
      Jason Brooks
      As Editor in Chief of eWEEK Labs, Jason Brooks manages the Labs team and is responsible for eWEEK's print edition. Brooks joined eWEEK in 1999, and has covered wireless networking, office productivity suites, mobile devices, Windows, virtualization, and desktops and notebooks. Jason's coverage is currently focused on Linux and Unix operating systems, open-source software and licensing, cloud computing and Software as a Service.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.