Linux PR Menu   
Affiliate site of

2008 Security Forecast: 'Least Privilege' Engineering Will Gain Momentum
  Jan 9th, 00:53 UTC

Human error and evolving phishing attacks will compel organizations to tighten control over application access, not just user access.

FOR IMMEDIATE RELEASE:

Allendale, New Jersey, January 8th, 2008 - Guardian Digital, the open source security pioneer, forecasts an increased need for comprehensive control over Internet and employee resources with 'least privilege' engineering in 2008. "Most vendors don't stress least privilege enough in their development architecture, especially with the increasing threats from human error and employee liability" says CEO Dave Wreski. "Security in 2007 has shown just how effective attackers can be at gaining authorized access to corporate resources. One of the best ways to protect against this is to lock down application access, not just user access."

Analysts are in agreement that phishing attacks will increase to an unprecedented level in 2008, especially targeted attacks made possible from social networking sites. As a result, Guardian Digital forecasts the new year will mark renewed buzz on the advantages of 'least privilege' in platform and application development.

Least privilege is the concept of giving access to applications based only on what is required for them to work, and no more. Pursuing this strategy can provide a tremendous benefit for security. Since application access is minimized, corporate resources remain much more secure, something that can be difficult when the platform and applications come from different vendors.

"The increased effectiveness of social engineering will propel least privilege back into the spotlight this year," Wreski continues. "The buzz on network security will decrease as there is an increased focus on solutions that combine platform and application development to reduce the risk of successful phishing attacks."

One example is the danger from web services. Without least privilege engineering, a tricked employee could allow an attacker to run an exploit on an Apache web server through a browser. Robust development driven by 'least privilege' can restrict this from within the application architecture, not just based on the privilege of the exploited user. If done properly, the web application can be engineered to explicitly run only the processes necessary, and will "jail" the attackers exploit, stopping it dead.

This requires experienced engineering that comes from developing both the operating platform and the applications, and integrating security into both. "Vendors that develop both," says Wreski "will be in a better position to successfully integrate least privilege into the corporate environment. We are proud to have emphasized this strategy with EnGarde Secure Linux since our founding in 1999 and will look to take advantage of the increased focus as the year progresses."

About Guardian Digital:
Leveraging the inherent benefits of open source architecture and the knowledge of security experts around the world, Guardian Digital has engineered the first, truly secure open source operating platform EnGarde Secure Linux. The secure Internet infrastructure of the award-winning EnGarde platform and its accompanying suite of applications guarantee online information assets remain protected even as Internet threats continue to evolve. Customized to meet the specific needs of any size enterprise, Guardian Digital's solution portfolio includes intrusion detection, Web services, secure remote access, information privacy and robust Email spam and virus protection.


(Submitted by Ryan Berens of Guardian Digital)

Return to today's headlines.

Linux Today

Linux Today

PR: Texas Opens the Door for Linux
InfoWorld: A Database Query
CNN: MySQL: A Threat to Bigwigs?
SearchEnterpriseLinux: Oracle Lends Support to UnitedLinux
Computerwire: Linux Is Replacing Windows Says Researcher

Search Linux Today:


All times are recorded in UTC.
Linux PR is an affiliate of the Linux Today network.
(webmaster@linuxpr.com)
Linux is a trademark of Linus Torvalds.
Powered by Linux and Apache


JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES