Linux fights off worms

Red Hat's Linux modified to cut scope for worm atttacks

Written by Roger Howorth

The forthcoming Red Hat Enterprise Linux (RHEL) 3 suite will include a new feature to thwart worms and hackers.

The news arrives as the security of open-source systems comes under increased scrutiny. Less than two weeks ago, several serious security vulnerabilities were revealed in OpenSSH and Sendmail, two popular open-source software packages.

The RHEL 3 server operating system, due to ship within weeks, includes a feature called Position Independent Executables (PIE). This is a modification to the Linux kernel developed by Red Hat to reduce the threat from worms and other buffer-overflow based attacks.

Red Hat has adapted a number of open-source programs for use with PIE, which causes the kernel to put them into different memory locations each time they are loaded. Experts say that hackers need to know the relative locations of programs and libraries in order to exploit buffer overflows. And worms must be tuned for each set of memory locations.

"There will always be bugs in software," said Mark Cox of Red Hat's security response team. "Even programming text books have flawed code. But buffer overflows should not be exploitable by hackers."

Cox argued that the best way to prevent buffer overflows from being exploited is to increase the diversity of software and, in particular, to randomise the locations where programs load and store their various components.

"This would make it impossible to write worms," he added.

Tags:

reader comments

related articles

Red Hat refashions Linux

The leading Linux vendor says its upcoming enterprise release has been shaped by corporate feedback 26 Sep 2003

 

Red Hat unveils KVM virtualisation portfolio

Release includes a new Linux-based standalone hypervisor 23 Feb 2009

Top 10 themes from RSA

The best of this year's security show 25 Apr 2009

Worm emerges for latest Microsoft flaw

Attacks reported on recently-patched Windows hole 05 Nov 2008

related whitepapers

today's top stories

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

Habitat gets a web site makeover

The furniture retailer is revamping its online presence to provide a fully transactional web site. CIO Jacques Dekock explains why 02 Jul 2009

Government aims to bolster UK's cyber defences

Is the UK’s first national cyber security strategy up to the task of co-ordinating the country’s response to digital threats? Computing investigates 02 Jul 2009

Focus resources on what really matters

IT has become too caught up in the drive for efficiency, at the expense of business success 02 Jul 2009

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Phil PavittAnalysis

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

UPS worker making a deliveryAnalysis

Global standardisation delivers benefits at UPS

Delivery giant sees benefits of central IT solution 02 Jul 2009

Advertisement

Primary Navigation