Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
67

Evaluating Encryption Needs In Modern IT Infrastructure

Encrypting every piece of data at rest within an organization could be expensive overkill. According to Al Kirkpatrick, chief security officer at information services firm First American Corp., many users may not need as much encryption as some industry sources are advocating. Kirkpatrick, whose firm provides services such as document processing to the real estate industry, explained that he is responsible for "billions of records stored on terabytes of data," during his Interop keynote Tuesday. According to the exec, this includes the world's largest Microsoft SQL Server database. . But the security chief warned other IT managers not to buy into the "soundbite du jour" of encrypting all this information. "The jive that bothers me is that you have got to drop everything and encrypt all data at rest at the moment," he explained. "You have got to look at the whole puzzle -- you're not going to have enough money to do it all." A number of vendors, including Decru, EMC, StorageTek, and IBM, are targeting this space, and a slew of offerings are available to encrypt data. (See Quantum, Decru Hook Up, IBM Certifies Decru, Decru Joins StorageTek Program, and Analysis: Storage Security .) The link for this article located at Dark Reading is no longer available. . Evaluating the genuine necessity for data protection: perspectives from security experts regarding expenses and efficiency.. Data Encryption, Encryption Strategy, IT Security, Cost Management. . LinuxSecurity.com Team

Calendar%202 May 03, 2006 User Avatar LinuxSecurity.com Team Cryptography
77

Effective Strategies for Database Encryption and Data Protection

Security is becoming one of the most urgent challenges in database research and industry, and there has also been increasing interest in the problem of building accurate data mining models over aggregate data, while protecting privacy at the level of individual records. Instead of building walls around servers or hard drives, a protective layer of encryption is provided around specific sensitive data-items or objects. . . .. Written by Ulf T. Mattsson, Chief Technology Officer, Protegrity Corporation. Security is becoming one of the most urgent challenges in database research and industry, and there has also been increasing interest in the problem of building accurate data mining models over aggregate data, while protecting privacy at the level of individual records. Instead of building walls around servers or hard drives, a protective layer of encryption is provided around specific sensitive data-items or objects. This prevents outside attacks as well as infiltration from within the server itself. This also allows the security administrator to define which data stored in databases are sensitive and thereby focusing the protection only on the sensitive data, which in turn minimizes the delays or burdens on the system that may occur from other bulk encryption methods. Encryption can provide strong security for data at rest, but developing a database encryption strategy must take many factors into consideration. This paper presents a practical implementation of field level encryption in enterprise database systems, based on research and practical experience from many years of commercial use of cryptography in database security. We present how this column-level database encryption is the only solution that is capable of protecting against external and internal threats, and at the same time meeting all regulatory requirements. We use the key concepts of security dictionary, type transparent cryptography and propose solutions on how to transparently store and search encrypted database fields. In this paper we willoutline the different strategies for encrypting stored data so you can make the decision that is best to use in each different situation, for each individual field in your database to be able to practically handle different security and operating requirements. Application code and database schemas are sensitive to changes in the data type and data length. The paper presents a policy driven solution that allows transparent data level encryption that does not change the data field type or length. We focus on how to integrate modern cryptography technology into a relational database management system to solve some major security problems. The link for this article located at net-security.org is no longer available. . Employ effective encryption strategies to safeguard sensitive data in databases while ensuring compliance with regulations like GDPR and HIPAA. Database Encryption, Data Protection, Encryption Strategies, Security Solutions, Data Privacy. . LinuxSecurity.com Team

Calendar%202 Jul 28, 2004 User Avatar LinuxSecurity.com Team Server Security
67

Evaluating Encryption's Critical Role In Securing IT Post-Attacks

Many companies have reassessed their technology initiatives in the month since the tragic attacks on the United States. Some are focusing on security measures for IT systems while others are deepening efforts to secure facilities and intellectual property. Encryption technologies are . . . . Many companies have reassessed their technology initiatives in the month since the tragic attacks on the United States. Some are focusing on security measures for IT systems while others are deepening efforts to secure facilities and intellectual property. Encryption technologies are being used to protect electronically transmitted data as well as information that's stored or archived. The link for this article located at Information Week is no longer available. . Many companies have reassessed their technology initiatives in the month since the tragic attacks on. companies, reassessed, their, technology, initiatives, month, since, tragic, attacks. . LinuxSecurity.com Team

Calendar%202 Oct 15, 2001 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200