Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
"The situation we're in with advertising is a lot like where the banks are, where everyone has struggled with the fact that you can't trust the other end of the connection," says White Ops CEO Michael Tiffany. "It's the same cookies, user information, etc. But one is real, and the other is fake.". Tiffany, of course, is referring to the very real threat of botnets targeting ad campaigns by infecting the computers of actual customers and users. When it comes to dodging anomaly detection, this is a far more effective approach than attempting to steal credentials. The link for this article located at CSO Online is no longer available. . The rise of automated networks in online marketing poses a significant risk, exploiting individuals while skillfully evading security measures.. Ad Campaigns, Botnet Attacks, Cyber Threats. . Dave Wreski
Network managers looking for an inexpensive way to better secure traffic crossing their nets might want to check out a free application from Intoto. Intoto, a provider of security software for enterprise network equipment and CPE gateways, last week at Interop, introduced a stand-alone intrusion-prevention system (IPS) application that the company says will help small and midsize companies looking for enterprise-scale security tools. . IntruPro IPS software can be downloaded onto a standard Linux x86 server and plugs in to the network in front of or behind an existing firewall. The company says the application is designed to prevent intruders from exploiting existing vulnerabilities on customer networks and computers, the vendor says. IntruPro IPS uses signature detection, protocol anomaly and traffic-anomaly technologies to determine the source of potential threats and then alerts network administrators of the suspicious activity. It is designed with stateful application-inspection capabilities to help reduce false alarms, and because it sits in line with the firewall, as soon as the software detects an attack, it will drop the malicious packets before they reach their intended target, the company says. The link for this article located at Network World is no longer available. . IntruPro IPS application is installable on a regular Linux x86 server and integrates seamlessly into the existing network infrastructure.. Intrusion Prevention System, Linux Security Tools, Network Anomaly Detection. . Brittany Day
Although the number and intensity of distributed denial-of-service attacks are on the rise, users are hard-pressed to find tangible new services to help thwart or defend against such assaults.. . .. Although the number and intensity of distributed denial-of-service attacks are on the rise, users are hard-pressed to find tangible new services to help thwart or defend against such assaults. However, the largest ISPs are doing more behind the scenes and are promising new tools by next year that will help predict and better defend against worms and viruses that act like distributed DoS attacks and true distributed DoS strikes. "There have been more attacks in the last six months than there have been in the last 10 years," said Hossein Eslambolchi, president of AT&T Labs, at a recent press conference. Carnegie Mellon University's CERT Coordination Center for reporting Internet security problems backs up such claims. Through the end of September, there were 114,855 security breaches reported by users and ISPs, which is 32,761 more than all of 2002. These reports include all types of security policy violations from distributed DoS to hacker attack. Although there are more security violations, the types of distributed DoS attacks have not changed much in 12 to 18 months, says Paul Morville, director of product management at Arbor Networks Inc., which offers PeakFlow network behavior anomaly detection products to service providers. What has changed is the size and scope of these attacks. The link for this article located at ComputerWorld is no longer available. . With the increase in DDoS assaults, internet service providers are pledging upgraded resources to bolster defenses and safeguard against vulnerabilities.. DDoS Security, Network Defense Tools, ISP Strategies, Internet Security Trends, Anomaly Detection. . Anthony Pell
"To some, our observations can be summarized succinctly as "bugs happen". That certainly is not news. But dismissing our results so cavalierly misses. . .. "To some, our observations can be summarized succinctly as "bugs happen". That certainly is not news. But dismissing our results so cavalierly misses the point. Yes, bugs happen. But bugs can be fixed -if they are detected. The Internet is, as a whole, working remarkably well. Huge software packages (i.e., X11R5) can be distributed electronically. Connections span the globe. But the very success of the Internet makes some bugs invisible." - Steven Bellovin [1] This excerpt, from the well-known 1993 report Packets Found on an Internet, was written nearly nine years ago. As we all know, times have changed. Today, such "bugs", are likely part of an attempt to breach network security. The investigation of strange packets, the cited paper's topic, is now quite common. We know it as intrusion detection. In the past few years, intrusion detection systems have joined firewalls as the fundamental technologies driving network security. In the near future, a third component will emerge - anomaly detection. The link for this article located at Security Focus is no longer available. . Grasping the progression of anomaly identification in cybersecurity and its approach to tackling application flaws and breaches.. Anomaly Detection, Network Security Solutions, Intrusion Detection Systems. . Anthony Pell
Programmers and software developers interested in security applications for component technology should keep tabs on work underway at Stanford Research Institute (SRI) International, a nonprofit research institute based in Menlo Park, California. Stanford Research Institute (SRI) has been tasked by the . . . . Programmers and software developers interested in security applications for component technology should keep tabs on work underway at Stanford Research Institute (SRI) International, a nonprofit research institute based in Menlo Park, California. Stanford Research Institute (SRI) has been tasked by the Defense Advanced Research Projects Agency (DARPA) to develop ways to use component technology to distribute real-time security monitoring throughout enterprise networks. According to Phillip Porras, program director of network security for SRI, the components emerging from DARPA's project, aptly named the Event Monitoring Enabling Responses to Anomalous Live Disturbances (EMERALD), are capable of providing anomaly and misuse detection for networks of all sizes. The link for this article located at IBM [linuxtoday] is no longer available. . Keep updated on EMERALD's strategy for improving network protection through the application of component technology for instantaneous oversight.. Component Security, Network Monitoring, Software Applications, Anomaly Detection, Enterprise Security. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.