On CBSSports.com: Mike Tyson's daughter dies in accident
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Dec 22, 2004 9:25:00 PM

Unpatched Linux systems are surviving longer on the Internet before being compromised, according to a report from the Honeynet Project released this week.

The data, from a dozen networks, showed that the average Linux system lasts three months before being compromised, a significant increase from the 72 hours life span of a Linux system in 2001. Unpatched Windows systems continue to be compromised more quickly, sometimes within minutes, the Honeynet Project report stated.

The results are probably due to two trends, said Lance Spitzner, president of Honeynet, which develops software for deploying computer systems as bait for online attackers. The default installations of new Linux systems are much more secure than previous versions of the open-source operating system, he said. Secondly, attackers seem to be much more concentrated on Windows systems than on Linux systems, and on attempting to fool desktop users, of which the vast majority use Windows.

"Everybody is focused on Windows," Spitzner said. "There is more money (for an attacker) to be made on the Windows systems."

The study is the latest data on the relative security of Linux systems versus Microsoft Windows. Last week, students found dozens of flaws in software that runs on Linux systems, and a research report stated that a thorough analysis of the Linux kernel turned up hundreds of flaws. However, in relative terms, those numbers are low compared to commercial applications.

Honeynets, a term coined by the project, are networks of computers that are placed on the Internet with the expectation that they will be compromised by attackers. The networks are heavily monitored, and the data is used to research the latest tactics of online miscreants.

While some of the Windows XP systems on the honeynets used for the latest study were compromised within minutes of being placed on the Internet, newer versions of the Linux operating system from Red Hat failed to be compromised by random attacks for more than two months.

Debbie Fry Wilson, director of product management for the security response center at Microsoft, told CNET News.com that the company's latest operating system is more secure than the report suggests.

"While it is not clear which version of Windows was used during the study, we feel that a Windows XP SP2 configuration with the Windows firewall enabled is the most resilient client operating system available in the market and can withstand attack much longer," Wilson said. "We are pleased that the report indicates that two Windows-based honeynets in Brazil withstood attack for several months. However, we are not certain that the report provides conclusive data based on a controlled and scientific study comparing the two operating systems."

Every Windows system compromised during the study had its security breached by a worm.

However, Spitzner stressed that the Honeynet Project does not have enough Windows systems deployed to offer meaningful data on that operating system's security. Moreover, the report does not specify what version of Windows XP had been running on the systems that had been compromised and whether any Service Pack upgrades had been installed.

The study did find that more recent versions of the Linux operating system lasted longer on the Internet without patching.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 23 Talkback(s)
Linux lasting longer against Net attacks
Folks:
I have had a Linux Mail Server/Firewall/Honeypot/Sandbox done on a K-6-400 old workstation using Libranet Linux for "3 YEARS" without any failure of the system except a little hardware ... (Read the rest)
Posted by: Inventor_z Posted on: 01/03/05 You are currently: a Guest | | Terms of Use
No surprise here (nt)  voska | 12/22/04
I guess the M$hills fail math... in addition to security.  Xunil_Sierutuf | 12/22/04
Not necessarily ...  worknman | 12/22/04
Exactly  d_jedi | 12/22/04
very good question work..  Monkey_MCSE | 12/22/04
article a few weeks ago  voska | 12/23/04
This is perhaps the point  hipparchus2000 | 12/26/04
And sadly they administer your bank accounts  FilledOut | 12/22/04
So kiss a little longer, longer with fresh breath!  Jeff Spicoli | 12/22/04
HA!  Loverock Davidson | 12/22/04
Heehee..this movie is too CLASSIC!  Jeff Spicoli | 12/22/04
WinXP SP2  crash89 | 12/22/04
Well, yet another study ...  George Mitchell | 12/22/04
Most stick with Windows...  DarthRidiculous | 12/28/04
Paging Dr. No_Ax, Pagin Dr. No_Ax!!  itanalyst | 12/22/04
Everyone! Look I am happy Linux is getting pretty  Laff | 12/23/04
"but a study"  PA-ITGuy | 12/23/04
How applicable is this test?  seosamh_z | 12/24/04
Ya know I would LOVE to see that patient test!  Laff | 12/26/04
Scientific method  Jiim_z | 12/29/04
Calling all good Microsoft citizens!  Sniper_z | 12/24/04
You'd need to call the bad ones  FilledOut | 12/27/04
Linux lasting longer against Net attacks  Inventor_z | 01/03/05

What do you think?

advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
advertisement
Click Here