Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 439
Alerts This Week
Warning Icon 1 439

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -1 articles for you...
79

Integrating SEM Technology With Current Management Infrastructure

Integrating SEM (security event management) technology with existing security and system management infrastructure can be a hair-raising experience. Security point products such as IDSes, anti-virus gateways, and vulnerability scanners tend to use proprietary formats for reporting, recording network events, and issuing alerts. . . .. Integrating SEM (security event management) technology with existing security and system management infrastructure can be a hair-raising experience. Security point products such as IDSes, anti-virus gateways, and vulnerability scanners tend to use proprietary formats for reporting, recording network events, and issuing alerts. And the standard formats that do exist -- such as SNMP and syslog files -- are limited in what they can convey. Today, SEM vendors get around the limitations by relying on custom plug-ins or software agents for each security or system management product they want to interact with. For example, Computer Associates (Profile, Products, Articles) has more than 100 integration kits that allow its eTrust Security Command Center to digest data from third-party security software. Most vendors also offer tools or services to integrate information from unsupported products or custom software applications. To simplify integration and management, universally accepted standards are required so that network end points, security products, and system management platforms can speak a common language. "An event's not meaningful if we can't define it. We need a well-defined schema and standards so that any system can generate an auditable event, then have [another system] receive it, classify it, store it, and do analysis," says Arvind Krishna, vice president of security and provisioning development at IBM (Profile, Products, Articles) Tivoli. The link for this article located at infoworld.com is no longer available. . Integrating SEM (security event management) technology with existing security and system management . integrating, (security, event, management),technology, existing, security, system, management. . LinuxSecurity.com Team

Calendar%202 Nov 01, 2004 User Avatar LinuxSecurity.com Team Security Projects
78

Network Intelligence EnVision 2.1: Enhanced Security Oversight and Insight

Improved User Interface Enables Centralized View of Global Network Security; Minimizes Time and Effort Associated with Managing Multiple Networks . . .. Improved User Interface Enables Centralized View of Global Network Security; Minimizes Time and Effort Associated with Managing Multiple Networks Network Intelligence(TM) Corp., the leader in appliance-based security event management (SEM), today announced the release of enVision(TM) 2.1, the newest version of the company's SEM software, which increases its capabilities with the introduction of an intelligent security awareness window (ISAW); asset correlation; built-in correlation rules; enhanced management filtering, bulk modification and inventory reports; and new device support. These new features enable faster and more efficient network and security device management, giving network administrators the ability to conduct deeper analysis of distributed data and providing the means to better protect their networks from potential security breaches. The link for this article located at TMCNet is no longer available. . Upgraded platform elevates worldwide cybersecurity control performance; discover enVision 2.1 functionalities and advantages.. Network Management, Security Analysis, Data Correlation, Real-Time Monitoring. . LinuxSecurity.com Team

Calendar%202 Oct 04, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
78

Inkra Networks and eIQnetworks Partnership for Enhanced Reporting

Inkra Networks, the leading provider of virtualized networking and security infrastructure, and eIQnetworks(TM), Inc., a leading provider of award-winning security, applications, and systems analytics solutions, today announced a partnership in which eIQnetworks will provide enhanced security and bandwidth analysis, monitoring, and reporting capabilities for Inkra's Virtual Service Switches (VSSs). . . .. Inkra Networks, the leading provider of virtualized networking and security infrastructure, and eIQnetworks(TM), Inc., a leading provider of award-winning security, applications, and systems analytics solutions, today announced a partnership in which eIQnetworks will provide enhanced security and bandwidth analysis, monitoring, and reporting capabilities for Inkra's Virtual Service Switches (VSSs). The partnership marks the interoperability of Inkra's VSS, the industry's leading virtualized networking and security solution, and the eIQnetworks FirewallAnalyzer Enterprise, the industry's only system analysis tool with the capability to monitor and report on individual virtualized applications. FirewallAnalyzer Enterprise is the only vendor-neutral, centralized security event management solution to deliver real-time auditing and investigative analysis of virtualized network security devices. This provides the ability to monitor and report on Inkra's virtualized security services, which include multiple instances of firewalls, and intrusion detection and prevention (IDP) modules. With hundreds of specialized reports, FirewallAnalyzer Enterprise provides a centralized view of security across the enterprise, significantly reducing the complexity of security analysis and providing IT managers with insight into both external attacks as well as internal network users who are violating corporate policies. The link for this article located at BUSINESS WIRE is no longer available. . Inkra Technologies enhances data monitoring and threat assessment through collaboration with eIQnetworks, ensuring improved networksafeguarding.. Network Protection, Bandwidth Analytics, Security Collaboration. . LinuxSecurity.com Team

Calendar%202 Sep 21, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
74

User Access Control Evolution and Life Cycle Management

Security management will evolve into three functional areas: user, event, and configuration management. User management aggregation (identity management and provisioning) will mature rapidly (2004). Security event management consoles (collecting intrusion detection system, firewall, and host events) will remain out of the . . . . Security management will evolve into three functional areas: user, event, and configuration management. User management aggregation (identity management and provisioning) will mature rapidly (2004). Security event management consoles (collecting intrusion detection system, firewall, and host events) will remain out of the mainstream until 2005. Security configuration consoles (central distribution points for firewall, personal firewall, and eventually server configurations/policies) are least mature, with viable integrated products appearing in 2006/07. Traditionally, user management is chaotic in most G2000 organizations, with requests coming from various channels (paper forms, phone calls, e-mails, help desk requests, etc.), and moving through various de facto fulfillment procedures. Often, a security or security administration group is involved in performance of the user management process (for internal users, while external users are often managed through a more coherent process--owing either to their larger scale, or to their status as "outsiders"). As organizations adopt a more holistic, process-centric view (2003/04) and move toward automation (2002-05), we expect security groups to involve themselves only in policy management, process design, and compliance monitoring, while the help desk or operations group owns the execution of the process (2006). Human resources, sales, or other business areas will have increasing input (2005/06) in policy development and, in some decentralized or federated organizations, may even own the process execution. Taking the process view, we find that users should have a "life cycle" of access to systems, applications, and databases (with adefined beginning and end, as well as changes in between). Unfortunately, in many organizations, users accumulate access over time, and when the user separates from the organization, that access continues (about 30 percent of users do not have access removed, according to recent Meta Group surveys, resulting in a perceived 23 percent increase in risk). Looking at this user life cycle, we find three distinct phases: provisioning, maintenance, and termination. The link for this article located at ZDNet is no longer available. . The evolution of security management has advanced across user, event, and configuration domains, enhancing access control mechanisms for better security.. User Access Management, Identity Lifecycle, Access Governance. . Anthony Pell

Calendar%202 Sep 18, 2002 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200