Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Google recognizes that before you can understand something, you need to measure it, and is bringing a way to measure security errors across open-source software programs. . Business author and expert, H. James Harrington, once said, "If you can't measure something, you can't understand it. If you can't understand it, you can't control it. If you can't control it, you can't improve it." He was right. And Google is following this advice by introducing a new way to strengthen open-source security by introducing a vulnerability interchange schema for describing vulnerabilities across open-source ecosystems. That's very important. One low-level problem is that there are many security vulnerability databases, there's no standard interchange format. If you want to aggregate information from multiple databases you must handle each one completely separately. That's a real waste of time and energy. At the very least you must create parsers for each database format to merge their data. All this makes systematic tracking of dependencies and collaboration between vulnerability databases much harder than it should be. . The latest framework introduced by Google aims to improve our approach to identifying and analyzing vulnerabilities in open-source applications.. Open Source Safety,Vulnerability Tracking,Security Measurement,Data Standards,Software Security. . LinuxSecurity.com Team
Integrating SEM (security event management) technology with existing security and system management infrastructure can be a hair-raising experience. Security point products such as IDSes, anti-virus gateways, and vulnerability scanners tend to use proprietary formats for reporting, recording network events, and issuing alerts. . . .. Integrating SEM (security event management) technology with existing security and system management infrastructure can be a hair-raising experience. Security point products such as IDSes, anti-virus gateways, and vulnerability scanners tend to use proprietary formats for reporting, recording network events, and issuing alerts. And the standard formats that do exist -- such as SNMP and syslog files -- are limited in what they can convey. Today, SEM vendors get around the limitations by relying on custom plug-ins or software agents for each security or system management product they want to interact with. For example, Computer Associates (Profile, Products, Articles) has more than 100 integration kits that allow its eTrust Security Command Center to digest data from third-party security software. Most vendors also offer tools or services to integrate information from unsupported products or custom software applications. To simplify integration and management, universally accepted standards are required so that network end points, security products, and system management platforms can speak a common language. "An event's not meaningful if we can't define it. We need a well-defined schema and standards so that any system can generate an auditable event, then have [another system] receive it, classify it, store it, and do analysis," says Arvind Krishna, vice president of security and provisioning development at IBM (Profile, Products, Articles) Tivoli. The link for this article located at infoworld.com is no longer available. . Integrating SEM (security event management) technology with existing security and system management . integrating, (security, event, management),technology, existing, security, system, management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.