Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Cybercrime is a massive global threat, and U.S. businesses are the No.1 target. For tips and advice about how best to defend against cyberattacks, Network World asked security pros to name their No.1, most valuable security tool. . Many of the experts we interviewed pointed out that there is no silver bullet when it comes to security. Ron Woerner, director of CyberSecurity Studies at Bellevue University put it this way: "There is no 'one and best' security tool. It really depends on the situation, circumstance, and personal preference. . Many of the experts we interviewed pointed out that there is no silver bullet when it comes to secur. cybercrime, massive, global, threat, businesses, target, advice. . LinuxSecurity.com Team
A new security tool developed by Department of Energy engineers is designed to give security and IT administrators the ability to more quickly identify and respond to an issue on the network. . Hone is the brainchild of Glenn Fink, a senior research scientist with the Secure Cyber Systems Group at the DOE The link for this article located at eWeek is no longer available. . Explore how Hone improves network oversight for rapid incident resolution and effective security administration.. Network Monitoring, Cyber Attack Response, IT Security Innovations. . LinuxSecurity.com Team
It's been a rough week for digital security in the USA, with China accused of hacking satellites and stealing secrets (claims they deny). Now it looks like the United States is planning on better readying itself for electronic threats by bumping up its cyber arsenal, both offensive and defensive. . At an event dubbed the "cyber colloquium," DARPA stated it needed to beef up its network security, and asked for academics, researchers, and "visionary hackers" to help it do so. With cyber-attacks a very real threat, DARPA wants to move away from plugging leaks, and on to prevent them from happening in the first place. The agency also has its sights set on being more prepared to use those capabilities offensively.. In a gathering named 'digital dialogue,' the NSA invites partners to improve defense mechanisms and tackle online vulnerabilities.. DARPA Cyber Initiative, Network Security Enhancement, Digital Threat Mitigation. . Dave Wreski
It will take several more years for the US government to fully install high-tech systems to block computer intrusions, a drawn-out timeline that enables criminals to become more adept at stealing sensitive data, experts say.. As the Department of Homeland Security moves methodically to pare down and secure the approximately 2400 network connections used every day by millions of federal workers around the world, experts suggest that technology already may be passing them by. The department that's responsible for securing government systems other than military sites is slowly moving all the government's Internet and e-mail traffic into secure networks that eventually will be guarded by intrusion detection and prevention programs. The networks are known as Einstein 2 and Einstein 3. . As the Department of Homeland Security moves methodically to pare down and secure the approximately . years, government, fully, install, high-tech, systems, block. . Anthony Pell
The switch from IPv4 to IPv6 will force many organizations to rethink the way their networks are defended. The result will be a shift away from the "guilty until proven innocent" attitude to incoming network traffic, toward one of "paranoid openness.". That's the view of Eric Vyncke, a Distinguished Engineer at Cisco Systems. Talking at the RSA Conference in London last month, he said that it is only when organizations become more open to incoming traffic that they will get the full benefits of IPv6. Many companies have delayed thinking about a move to the next generation IPv6 Internet protocol because there is little benefit in being a "first mover," but sometime in the next few years the remaining free IPv4 IP addresses will be used up. When that happens the world will be forced over time to move to IPv6, which offers 128 bit addresses (instead of IPv4's 32 bit addresses), resulting in a staggering 2 ^ 128 different possible IP addresses . That's more than enough to assign a unique IP address to every atom on the surface of the earth, let alone every network connected server, desktop computer, laptop, smartphone, Web camera, and any other device that will ever be manufactured and connected to a corporate network. The benefits for many organizations of this end-to-end IPv6 connectivity could be very significant indeed. The link for this article located at Enterprise Networking Planet is no longer available. . The transition to IPv6 requires a thorough evaluation of security protocols due to its distinct features compared to IPv4, enhancing risk management and defense. IPv6 Security,Cybersecurity Strategies,Network Defense Policies. . Anthony Pell
The U.S. government is shifting its strategy for defending federal networks against a rising tide of hacking attacks launched by foreign governments and criminals. Instead of focusing on consolidating external Internet connections that civilian agencies operate -- which number in the thousands -- the Office of Management and Budget is directing agencies to deploy a standard set of security tools and processes on all of their Internet connections.. The shift represents a new direction for the federal Trusted Internet Connections (TIC) Initiative, which was launched by the Bush administration in November 2007. The Bush administration's original goal was to reduce the number of external Internet connections operated by civilian agencies from more than 8,000 down to 50. Standard security software -- including antivirus, firewall, intrusion detection and traffic monitoring -- was to be deployed on the remaining connections. The Obama administration has changed the emphasis of the TIC Initiative, focusing more on security controls than on network consolidation. "Despite the whole TIC Initiative, there are probably as many points of Internet connection as there used to be," says Diana Gowen, senior vice president of Qwest Government Services. "The new administration is less concerned with the number, and more concerned about getting them protected." Gowen pointed out that the Defense Department has an ongoing procurement to purchase more than 4,000 Internet connections worldwide. "So clearly the focus isn't on consolidation," she adds. The link for this article located at Network World is no longer available. . The shift represents a new direction for the federal Trusted Internet Connections (TIC) Initiative, . government, shifting, strategy, defending, federal, networks, against, rising. . Alex
It isn. Larger companies hire full-time staff to secure their networks and keep them secure from the constant barrage of security-smashing attempts by those malcontented demons living in some squalid and unpronounceable distant land. That The link for this article located at Linux Magazine is no longer available. . Larger companies hire full-time staff to secure their networks and keep them secure from the constan. secure, larger, companies, full-time, staff, their, networks. . Alex
Sometimes a rule configuration may reside in a place other than the basic rule configuration place. In such a case, it is difficult to confirm whether it is an intended configuration by the system administrators. (Is an unnecessary hole open, or is a necessary hole open?) So, we developed a tool which checks the rule of a Firewall. " In any network your first line of defense is the firewall. One new firewall checker is called Dr.Morena. It's made up of two modules one is the check engine and the other is the packet list making engine. They work on Linux so it's good at checking your iptables. Go ahead and test your firewall to see how well it protects your network. . Dr.Morena is a tool to confirm the rule configuration of a Firewall. The configuration of a Firewall is done by combining more than one rule. Sometimes a rule configuration may reside in a place other than the basic rule configuration place. In such a case, it is difficult to confirm whether it is an intended configuration by the system administrators. (Is an unnecessary hole open, or is a necessary hole open?) So, we developed a tool which checks the rule of a Firewall. The link for this article located at security Friday is no longer available. . Dr. Vega analyzes your encryption protocols and strengthens data security measures.. Firewall Tool, Iptables Checker, Network Defense, Dr.Morena. . Bill Locke
Get the latest Linux and open source security news straight to your inbox.