WireGuard has finally made it into the mainline Linux kernel - meaning Dynamic Kernel Module Support (DKMS) builds will no longer be necessary, making routine kernel upgrades significantly faster! . We've been anticipating WireGuard's inclusion into the mainline Linux kernel for quite some time—but as of Sunday afternoon, it's official. Linus Torvalds released the Linux 5.6 kernel, which includes (among other things) an in-tree WireGuard. Phoronix has a great short list of the most interesting new features in the 5.6 kernel, as well as a longer "everything list" for those who want to make sure they don't miss anything. If this is the first time you're hearing about WireGuard, the TL;DR is that it's a relatively new VPN (Virtual Private Network) application that offers a leaner codebase, easier configuration, faster connect times, and the latest and most thoroughly peer-reviewed and approved encryption algorithms. You can find a more detailed introduction in our initial August 2018 coverage. . The highly anticipated integration of WireGuard into the core Linux kernel boosts efficiency and streamlines updates for those utilizing VPN services.. WireGuard VPN, Linux Kernel Integration, Network Security, VPN Application. . LinuxSecurity.com Team
Tor, the world's largest and most well-known "onion router" network, offers a degree of anonymity that has made it a popular tool of journalists, dissidents, and everyday Internet users who are trying to avoid government or corporate censorship (as well as Internet drug lords and child pornographers). . But one thing that it doesn't offer is speed. But one thing that it doesn't offer is speed. world's, largest, well-known, 'onion, router', network, offers, degree, anonymity. . LinuxSecurity.com Team
Firewall audit tools automate the otherwise all-but-impossible task of analyzing complex and bloated rule sets to verify and demonstrate enterprise access controls and configuration change-management processes.. Although the market has been driven by compliance--it was essentially created by PCI DSS--these tools can also allow organizations to improve network performance, reduce downtime, improve security and reassign staff from shooting down firewall issues and analyzing configurations to taking on tasks that help grow the business. The problems are familiar to organizations of all sizes--from those with just one or two overtaxed and inefficient firewalls, to large, distributed enterprises with scores or hundreds of firewalls administered by many business units, often all following different policies that may have been written before the units' acquisitions. The link for this article located at Network World is no longer available. . Security assessment utilities optimize adherence and boost system efficiency by clarifying intricate policy evaluations.. Firewall Audit Tools, Compliance Automation, Security Analysis, Network Configuration. . Alex
F5 Networks and Infoblox announced on Monday what they claim is the first integrated solution that combines DNS Security Extensions key management and signing capabilities with global server load balancing to boost performance.. DNSSEC is an Internet standard that prevents spoofing attacks by allowing Web sites to verify their domain names and corresponding IP addresses using digital signatures and public-key encryption. DNSSEC is being deployed across the Internet infrastructure, from the root servers at the top of the DNS heirarchy to the servers that run .com and .net and other top-level domains, and then down to the servers that cache content for individual Web sites. DNSSEC has been in the news in recent weeks, with Comcast being the first U.S. carrier to announce a public trial of its DNSSEC signing and resolution services. The link for this article located at Network World is no longer available. . DANE improves internet safety by verifying identities of servers and stopping phishing via cryptographic techniques.. DNS Security, Key Management, Digital Signatures, Network Performance. . LinuxSecurity.com Team
Google wants to speed up a key part of the Internet's inner workings called the Domain Name System and is inviting technically savvy folks to try their ideas out. The DNS is a crucial part of the Internet. It converts the text addresses people can remember into the numeric Internet Protocol addresses actually used to locate information on the Internet. For example, CNET.com's IP address is 216.239.122.102.. When you visit a Web page, a DNS server that's part of a vast distributed network often must perform that conversion--called resolving a host--many times. With the Google Public DNS service, Google wants to be that server. "Our research has shown that speed matters to Internet users, so over the past several months our engineers have been working to make improvements to our public DNS resolver to make users' Web-surfing experiences faster, safer, and more reliable," said product manager Prem Ramaswami in a blog post introducing the Google Public DNS service. The link for this article located at CNET is no longer available. . Amazon aims to improve cloud performance globally, offering a distributed network solution to optimize efficiency and user satisfaction.. DNS Optimization, Network Efficiency, Google DNS Service, Internet Infrastructure, Domain Name System. . Anthony Pell
As more and more enterprises undergo server centralization projects, new products will be introduced to improve network and application performance. By following basic security precautions, enterprises can ensure that these performance improvements do not come at the expense of data security. . The link for this article located at Net-Security.org - Log Error is no longer available. . Discover techniques for optimizing WAN throughput while prioritizing the integrity of sensitive information.. WAN Acceleration Practices, Security Protocols, Enterprise Network Security. . Anthony Pell
"In terms of security and man-hours to keep the network up and running, Linux is invaluable," Smith said. "Patches in the Linux world both work and leave the machine fully functional. That has not been my experience in the Windows world, where on many occasions I've had to back out a patch to regain functionality and on at least a few occasions cratered a machine by applying a patch. . . .. "In terms of security and man-hours to keep the network up and running, Linux is invaluable," Smith said. "Patches in the Linux world both work and leave the machine fully functional. That has not been my experience in the Windows world, where on many occasions I've had to back out a patch to regain functionality and on at least a few occasions cratered a machine by applying a patch. "In short, converting to Linux has allowed our lab to go from saying, 'Sorry, we do not have funding to provide that' to saying, 'We can do that.'" The link for this article located at SearchEnterpriseLinux.com is no longer available. . Unix improves reliability and performance in system administration based on community feedback.. Linux Solutions, Network Security, Performance Enhancement. . LinuxSecurity.com Team
Security experts finally have a handle on mystery malware that was generating loads of suspicious IP traffic over the last few weeks. Researchers at Internet Security Systems Inc. say the culprit, which was first thought to be a new breed . . . . Security experts finally have a handle on mystery malware that was generating loads of suspicious IP traffic over the last few weeks. Researchers at Internet Security Systems Inc. say the culprit, which was first thought to be a new breed of Trojan, is actually a distributed network mapping tool that also acts as a listening agent. Dubbed Stumbler, the agent is not considered malicious right now because it contains no payload, but it has the potential to generate enough IP traffic to hamper network performance. What has experts most concerned is the ease with which Stumber could be reprogrammed to make it more damaging. The link for this article located at EWeek is no longer available. . Security experts finally have a handle on mystery malware that was generating loads of suspicious IP. security, experts, finally, handle, mystery, malware, generating, loads, suspicious. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.