AWS is open sourcing its Cedar policy language and authorization engine and Snapchange, an open source snapshot-based fuzzing tool. . At the Linux Foundation Open Source Summit North America , Amazon Web Services (AWS) made not one, but two, important open source security announcements. First, the company is open sourcing its Cedar policy language and authorization engine . This tool allows developers to set intricate policy permissions within their applications that are separate from their application logic. The other, Snapchange , is an experimental venture into the potential of the Linux’s kernel’s built-in virtual machine program, KVM , for snapshot fuzzing. Cedar is already used by the Amazon Verified Permissions (AVP) , and AWS Verified Access managed services. It’s both a language and a software development kit (SDK) for building and enforcing application authorization policies. With Cedar, programmers can control access to resources such as data, compute nodes in a cluster, or workflow automation components, AWS claims it’s very flexible, and developers can specify fine-grained permissions with it. . Google reveals new AI-driven analytics platform, featuring DataLens visualization system and QuickInspect quality assurance tools.. Cedar Policy Language, AWS Security Tools, Open Source Fuzzing Toolkit. . Brittany Day
A new fuzzing tool, USBFuzz, has identified 18 USB bugs impacting Linux. Eleven have already been patched. . Academics say they discovered 26 new vulnerabilities in the USB driver stack employed by operating systems such as Linux, macOs, Windows, and FreeBSD. The research team, made up by Hui Peng from Purdue University and Mathias Payer from the Swiss Federal Institute of Technology Lausanne, said all the bugs were discovered with a new tool they created, named USBFuzz . . Researchers identified 31 additional flaws in the USB subsystem that supports various OS platforms.. Linux USB Bugs, Fuzzing Tool, Vulnerability Research, Driver Stack Issues. . Brittany Day
Tmin is a simple utility meant to make it easy to narrow down complex test cases produced through fuzzing. It is closely related to another tool of this type, delta, but meant specifically for unknown, underspecified, or hard to parse data formats (without the need to tokenize and re-serialize data), and for easy integration with external UI automation harnesses. Give this fuzzer a go and let us know what you think! Included in the article is a sample "hello world" script to fuzz "hello world" code, if that makes any sense. Why not check out the article to see what I mean?. The link for this article located at Darknet.org is no longer available. . Tmax serves as a resource for enhancing test scenarios within automatic security assessment, particularly for intricate data structures.. Test Case Optimizer,Fuzzing Tool,Automated Security Testing,Data Format Optimization. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.