About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
 COLUMN ARCHIVE  FORUMS
 

COLUMN

 
The Open Source
Russell Pavlicek

Security by numbers?

A RECENT Aberdeen Group report claims that open source is less secure than Windows.

   ADVERTISEMENT
  

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  IE 7 bug reopens debate over patch responsibilities
»  Woman ordered to pay for file-sharing will appeal
»  McAfee to buy SafeBoot for $350M
»  Security RSS feed 

IDG ENTERPRISE NETWORK
Research Reports  (CIO)
Ask the Expert  (CIO)

TOP NEWS 


IT SOLUTION SEARCH
And how did they come to this profound conclusion? Apparently, they counted the number of CERT advisories in the past couple of years and found more associated with open-source software than with Windows.

Unfortunately, that's like comparing the number of humans to ants and concluding that ants must be the dominant species due to their larger numbers. Simple numbers can yield incorrect conclusions when taken out of context.

So how can one do an intelligent comparison of security incidents?

Don't count duplicates. One security flaw in a utility can yield a separate report for each distribution that uses that utility. If five Linux distributions each have the utility, you have one real problem, not five.

Identify problems in distributions. Most companies run on code included in specific Linux or BSD distributions. Many security flaws found briefly on code from a developer's Web site are fixed before they make their way onto a distribution. So if your business is using Red Hat, count the bugs that actually appear in your version of Red Hat. Including bugs that appear in other distributions doesn't really tell you how exposed you are.

With most open-source operating systems, much of the software is not installed by default. For example, a flaw in Sendmail might be serious, but only if you have Sendmail installed. Many distributions use Postfix or Qmail to handle mail by default, so a Sendmail bug might mean nothing to you.

You cannot simply compare exploits in open source to Windows. Open source covers multiple operating systems, distributions, and programs. Even comparing a single distribution to Windows is flawed because a single distribution is likely to contain multiple office suites, database systems, and countless utilities that must be purchased separately in the Windows world. Instead, compare the total software on your typical Linux or BSD box to that of your typical Windows PC.

It isn't enough to consider the number of security holes. You need to know how quickly the patches occur. A hole that stays open for weeks can be far more dangerous than a few holes that can be closed in hours.

Don't assume that open-source software is inherently insecure because crackers can see the source code. History shows that crackers don't need source code to find exploits, but motivated technical people need source code to close holes. Open source restores the balance of power by allowing holes to be closed faster than software organization could manage.

Accurately evaluating security flaws might finally get statistics that mean something.


Russell Pavlicek is an independent open-source consultant. Contact him at pavlicek@linuxprofessionalsolutions.com. Log on to his forum at www.infoworld.com/os.




RELATED ARTICLES

Open source seeks growth in government market


RELATED SUBJECTS

Security

Discuss this article in our online forums

Click here for all of Russell Pavlicek's past columns.


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» IT Compliance Conference: Nov. 5-7 in San Diego
Best Practices, Peer Experiences, & Expert Advice for Building a Defensible IT Compliance Program
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» IT Audit Checklists
Prepare for your next internal IT audit. Checklists cover security, risk management, PCI, and more.
» FREE White Paper: Mitigating Rock Phish Attacks
Standard anti-phishing methods cannot defeat complex Rock Phish attacks. Learn how to fight back...
» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no