On BNET: 5 things to know about the Palm Pre
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Mar 23, 2005 12:56:00 AM

Companies face greater risks if they run their Web sites on Linux rather than Windows, a Microsoft-funded study has concluded.

Last year, Web servers based on Windows Server 2003 had fewer flaws to fix than those based on Red Hat Enterprise Linux ES 3 in a standard open-source configuration, researchers said in a paper released on Tuesday.

Moreover, the study indicated that the Microsoft-based Web server had far fewer "days of risk"--a measure of the number of days that each vulnerability is known, but unpatched--than the open-source rival.

"All this study can do is give people pause, to say they shouldn't go with common wisdom over which platform has more security," said

"We believe there to be inaccuracies."
--Mark Cox, security response team leader, Red Hat
Herbert Thompson, one of the three authors of the paper and the director of research and training at Security Innovations, a security applications company. The common belief is that Linux is more secure that Windows.

The paper has already caused controversy, as some details were presented at the RSA Conference last month. Previous studies comparing measures of security in Windows and Linux have also caused heated discussion.

"We believe there to be inaccuracies," Mark Cox, the leader of Red Hat's security response team, wrote about the recent study in a blog posted to the software company's Web site on Tuesday. He said that the study did not separate "critical" vulnerabilities from less serious ones, a comparison that would favor Red Hat.

Red Hat did not otherwise comment on the paper and referred requests for comment to the blog.

Counting the holes
For the study, researchers counted the fixes published for flaws in each Web server setup in 2004. In addition, they tallied days of risk, the cumulative number of days between the time information on a flaw is publicly released and the time the software developer patches that vulnerability.

A server using Red Hat Enterprise Linux ES 3 had more than 12,000 days of risk, while a Microsoft configuration had about 1,600, they said.

As for flaws, a Red Hat-based Web server with open-source Apache Web server software, MySQL database and the PHP scripting language had to deal with 174 holes in its default configuration, the study found. A Web server based on Microsoft Server 2003, Internet Information Server 6, Microsoft SQL Server 2000 and ASP.Net had 52 vulnerabilities in the default configuration.

The researchers also studied Red Hat and Windows Web servers in minimal configurations, taking out of consideration applications that are not needed for serving Web pages. Even in that case, Microsoft still handily beat Red Hat, with only 52 flaws, compared with 132 for the Linux software.

Red Hat's Cox countered the findings in his blog posting.

"There were only eight flaws in Red Hat Enterprise Linux 3 that would be classed as 'critical' by either the Microsoft or the Red Hat severity scales," he wrote. "Of those, three-quarters were fixed in a day, and the average was eight days."

Critical flaws are generally those that allow an attacker to remotely take control of a computer system. The study did break vulnerabilities down into "high," "medium" and "low" severity ratings. Flaws graded as high severity include Red Hat and Microsoft's critical classifications and flaws that allow local users to gain access to system functions. Microsoft had far fewer high-severity flaws in both the default and minimal configurations, according to the paper.

Microsoft did fund the study, the researchers acknowledged. The software giant released a statement on Tuesday that indicated

I think either is infinitely securable by a skilled Jedi administrator.
--Herbert Thompson, study author
the report was part of Microsoft's "Get the Facts" campaign aimed at highlighting the benefits of Windows software.

"When Security Innovations submitted a proposal to Microsoft to research ways to measure vendor software security, we evaluated the proposal and determined that this type of analysis would be useful for our customers and funded their research," the company said in the statement. "We encourage customers to review and evaluate the data in the context of their own computing environments."

Richard Ford, a computer science professor at the Florida Institute of Technology, and Fabien Casteran, a security test engineer at Security Innovations, were the authors of the report alongside Thompson. The researchers hope to stave off criticism by publishing their methods as part of the report.

"The methodology was designed to allow others to validate it for themselves--it has to be quantitative and repeatable," Thompson said. "We didn't just want to hand people the cake; we wanted to give them a recipe as well."

While both days of risk and vulnerability counts aren't true measures of security, Thompson said that they wanted to focus on a metric that mattered to system administrators. The cumulative time they had to wait for patches is a reasonable measure, he argued.

Thompson admitted, however, that security largely depends on the expertise of the administrator.

"I think either (operating system) is infinitely securable by a skilled Jedi administrator," Thompson said. "If I have a Linux guru, then I want that guy to do the Linux web server. I am more of a Window guru, so I would use Windows."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 266 Talkback(s)
Thank whoever for...
...a sensible statement at last.

I thought this "debate" was never going to get one.

Cheers, rudeboy.... (Read the rest)
Posted by: bargeemike Posted on: 04/04/05 You are currently: a Guest | | Terms of Use
Oh my, the comedy keeps rolling on!  Jeff Spicoli | 03/22/05
I guess this answers that IIS mystery ...  ShadeTree | 03/23/05
Let's be fair Shade....at least give Apple half the time  Laff | 03/23/05
If Apple takes security into mind ...  ShadeTree | 03/23/05
Well you just answered one of your own questions in  Laff | 03/23/05
DRM is mandated by the Music Companies ....  ShadeTree | 03/23/05
You hit the nail  htotten | 03/23/05
Actually NO...the iPod can handle WMA format anytime  Laff | 03/23/05
Actually No Indeed.  ShadeTree | 03/23/05
Sorry Shade...I'm not worried, Jobs is not worried, and  Laff | 03/23/05
RE: Sorry Shade  ShadeTree | 03/23/05
Once again only time will tell this tale. Still I can make  Laff | 03/23/05
RE: Laff  ShadeTree | 03/23/05
OK..and where here did I post such? I mean my biggest  Laff | 03/23/05
WHAT?!?!  Jeff Spicoli | 03/23/05
What?!  cashaww | 03/23/05
I probably won't lose any sleep over your contention(nt)  ShadeTree | 03/23/05
RE: If Apple takes security into mind ...  JakAttak | 03/23/05
Pay attention!  ShadeTree | 03/23/05
no, you called it a website  doh123 | 03/23/05
Hmm... From the pyMusique site:  thetargos | 03/23/05
RE: pyMusique  ShadeTree | 03/23/05
What an 1d10+...  MepisLINUXuser | 03/23/05
Except if you take your blinders off ...  ShadeTree | 03/23/05
yep, you have to look at what they did  doh123 | 03/23/05
Don't drink and think in future!  GetReal-mac.com | 03/23/05
Um not sure just what you were trying to say there  Laff | 03/23/05
Question  DWalker_z | 03/23/05
Yes  Jeff Spicoli | 03/23/05
Right on...  colotech | 03/23/05
What is this idiot talking about?  Reverend MacFellow | 03/23/05
The harm done ...  ShadeTree | 03/23/05
Comedy?  colotech | 03/23/05
Wow, what a surprise!  Monkeypox | 03/22/05
Could it be MS is concerned about getting outpaced?  djc1309@... | 03/25/05
In other news...  Letophoro | 03/22/05
cool  IT Scion | 03/22/05
we have done similar security studies and found Linux more sercure  matrixdomain | 03/22/05
(nt)Where are these studies published?  toadlife | 03/22/05
One good reason  Angel_LB | 03/23/05
That's fine, but...  toadlife | 03/23/05
Fine for *you*  SC-man | 03/23/05
we have done similar security studies and found Linux more secure  matrixdomain | 03/22/05
I use Linux and Windows XP.  Altimit | 03/22/05
Nice try son  toadlife | 03/22/05
I don't think so  MacGeek2121 | 03/23/05
Yes.... ^-^  Altimit | 03/23/05
So you are agree...  toadlife | 03/23/05
Can we get technical?  LinuxHippie | 03/24/05
Knoppix, HELLO!  Hrothgar - PCLinuxOS User | 03/30/05
Second fact about Linux and Windows security.  Altimit | 03/22/05
(nt) You and matrixdomain should form a Linux luser group  toadlife | 03/22/05
Where does Apache and Tomcat  bjbrock | 03/22/05
Well put . . .  Sheeva | 03/23/05
Honorable concepts but...  robradina@... | 03/23/05
Very very good point ...  OldFossil | 03/23/05
I'd comment, but....  KOS-MOS | 03/22/05
'd comment, but....  richdave | 03/22/05
'd comment, but....  bjpartida | 03/23/05
Clever  Richard Flude | 03/22/05
Read it for a luagh  Richard Flude | 03/22/05
I'm sure they are out there, but where  bjbrock | 03/22/05
Imagine that!  richdave | 03/22/05
They used Microsoft hackers  Ac303co@... | 03/23/05
Non-news  John L. Ries | 03/22/05
Not only would it not be published,  YaBaby | 03/23/05
Maybe right  John L. Ries | 03/23/05
Look can we ALL agree that included Anton and No Ax  Laff | 03/22/05
Agreed  NonZealot | 03/22/05
when was the last time Mozilla or Linux had more viruses?  matrixdomain | 03/22/05
I'll tell you Matry..  Jeff Spicoli | 03/22/05
so...  jdahs@... | 03/22/05
Yeah  Jeff Spicoli | 03/22/05
You bring up a good point  IT Scion | 03/22/05
Re: Agreed  Mack DaNife | 03/23/05
Here's one test  IT Scion | 03/23/05
Your link...  Mack DaNife | 03/23/05
Let's have a group hug?  seosamh_z | 03/22/05
Yup  Jeff Spicoli | 03/22/05
I agree Jim  Jeff Spicoli | 03/22/05
re:I agree Jim  school1012 | 03/23/05
yes...  jdahs@... | 03/22/05
LAME is great for mp3's  Anton Philidor | 03/23/05
For the most part I do agree Anton..still one should  Laff | 03/23/05
Studies have to be funded.  Anton Philidor | 03/23/05
Damn Anton mark this on the calender  Squawkbox | 03/23/05
Reality Distortion Field  MacGeek2121 | 03/23/05
Gosh Jim I wasn't going to reply to the story  Squawkbox | 03/23/05
I disagree.  Judas I. | 03/23/05
Roger that Jim!!! happy (nt)  tbbrickster_z | 03/23/05
Roger Roger. Under Over.  Jeff Spicoli | 03/23/05
What's our vector Victor? (nt)  Letophoro | 03/23/05
who does Microsoft thinks it's going to fool?  matrixdomain | 03/22/05
Ah,  darkmoonman | 03/23/05
Only risk is to Microsoft.  Xunil_Sierutuf | 03/22/05
Agree  Altimit | 03/22/05
Message has been deleted.  Altimit | 03/22/05
lol!  toadlife | 03/22/05
And there it is  IT Scion | 03/22/05
Are you happy..........  wjw@... | 03/23/05
Yet another classy Linux user  Salman Pak | 03/23/05
I am a Linux user  Mack DaNife | 03/23/05
Ahm... Mack.  Anton Philidor | 03/23/05
No, I made the point I wanted to.  Mack DaNife | 03/23/05
I'd like to think a reasonable argument...  Anton Philidor | 03/23/05
Anton,  Mack DaNife | 03/23/05
Since 60% of web defacements involve Linux...  toadlife | 03/22/05
Interesting stats  NonZealot | 03/22/05
What was interesting to me...  toadlife | 03/22/05
..And that is the bottom line.  antonparrish@... | 03/24/05
Thank whoever for...  bargeemike | 04/04/05
Statistics show otherwise  kokuryu | 03/23/05
Can you follow a link?  toadlife | 03/23/05
Stats from VilyClay.com?  seosamh_z | 03/23/05
Assuming your data point is accurate...  shadar | 03/23/05
Actually no  toadlife | 03/23/05
OT: MS closes on new 52-week low  Richard Flude | 03/22/05
This story is hit bait only!  osreinstall | 03/23/05
Troll-a-rama  Sunny Jalolly | 03/23/05
not quite...  jdahs@... | 03/23/05
They do their testing  osreinstall | 03/23/05
Lies, Damn Lies, and Statistics  Roger Ramjet | 03/23/05
This just in...!!!  John E Wahd | 03/23/05
Used Car Dealers & The IRS  phil@... | 03/24/05
Ya Think ?  BitTwiddler | 03/23/05
Microsoft just upped the grease they pay to ZDnet?  whisperycat | 03/23/05
You are funny in your zealotry!  NonZealot | 03/23/05
Zone H stats in closer detail  whisperycat | 03/23/05
Hehe, ANOTHER conspiracy!!  NonZealot | 03/23/05
Gud FUD NZ  whisperycat | 03/23/05
Prove it to me first  NonZealot | 03/23/05
If you respond caustically...  Anton Philidor | 03/23/05
Opinion pieces are not compelled to have credibility  whisperycat | 03/23/05
Fair enough  Anton Philidor | 03/23/05
That only works...  rapson | 03/23/05
really?  jdahs@... | 03/23/05
Furthermore, a real "computer scientist" would never...  toadlife | 03/24/05
Another Microsoft bribed site!!  NonZealot | 03/23/05
Your vulnerabilities do not include viruses!  whisperycat | 03/23/05
hmm...  jdahs@... | 03/23/05
Zone-H stats a year ago  toadlife | 03/23/05
Yes, of course.  bargeemike | 03/23/05
Why don'Face it  toadlife | 03/23/05
Hmmm....  bargeemike | 03/24/05
Zone-h Stats Irrelevant (lame)  whogoesthere | 03/23/05
Microsoft shill eh?  toadlife | 03/23/05
Yes Shill and still Irrelevant  whogoesthere | 03/24/05
You are wearing your emotions on your sleeve.  toadlife | 03/24/05
Microsoft didn't pay ZDNet to publish this.  Linux_Developer | 03/23/05
Wow...  droby10 | 03/23/05
(nt)That register article is an opinion peice written by a Linux advocate  toadlife | 03/23/05
Then I've officially lost all respect for the Linux community...  droby10 | 03/23/05
Technical Inaccuracies?  whogoesthere | 03/23/05
Patience is a virtue...(nt)  droby10 | 03/23/05
What Embarassment?  whogoesthere | 03/23/05
Truth Hurts  nucrash | 03/23/05
Laughing so hard I'll cry!  IAHawkeye | 03/23/05
...here's what i think.  droby10 | 03/23/05
And I think....  IAHawkeye | 03/23/05
I must enter a title for my message  droby10 | 03/23/05
How about windows security myths 101  IAHawkeye | 03/24/05
this title requirement is butt...  droby10 | 03/24/05
So true  Shift4SMS | 03/23/05
And I meant....  IAHawkeye | 03/23/05
Yeah, I know...  Shift4SMS | 03/24/05
re: Laughing so hard I'll cry!  segurajohn@... | 03/23/05
Who REALLY Knows?  mwagner@...ZDNet Moderator | 03/23/05
Good Answer from MWAGNER  ngibat@... | 03/23/05
But we wont  IT Scion | 03/23/05
Pepsi funded study concludes Coke could cause AIDS  Taz_z | 03/23/05
Coke study did show people preferred Pepsi.  Anton Philidor | 03/23/05
I read that too  Jeff Spicoli | 03/23/05
MICROBRAIN  Macmax77 | 03/23/05
ARREST LEMOS FOR FRAUD  JoeBob_z | 03/23/05
Where Oh Where Has My Bitty Dog Gone......  itanalyst | 03/23/05
Linux risker than Windows?  aaggarwal | 03/23/05
99% of foxes say henhouse locks a safety hazard...  dnwdfw | 03/23/05
MS Still Rules!!!!  school1012 | 03/23/05
What a Shocker  Yehuda Mann | 03/23/05
Lies, damned lies and Microsoft funded surveys  mormop | 03/23/05
The real outcome of the whole story is one line:  htotten | 03/23/05
blinders  jplace@... | 03/23/05
Risk...  jskline0@... | 03/23/05
Hear, hear!  Shift4SMS | 03/23/05
Microsoft-funded study? What wld you expect?  julie22 | 03/23/05
ROFLMAO  IT_Critic | 03/23/05
What's More Pathetic?  tbbrickster_z | 03/23/05
George Ou seems to be agree....  Scrat | 03/23/05
more Microsoft BS  unstable1 | 03/23/05
How much more can they lie?  kokuryu | 03/23/05
RE: How much more can they lie?  school1012 | 03/23/05
Most people in security...  droby10 | 03/23/05
Many people are glad you chose Linux  toadlife | 03/23/05
Boy, have we been clueless!  code_flogger | 03/23/05
Windows Server Are Better  school1012 | 03/23/05
My Windows application server has never been hit!  mark_a_riley@... | 03/23/05
what's the IP address or domain name?  matrixdomain | 03/23/05
That would be stupid  toadlife | 03/23/05
Huh? Windows will never approach Novell or Unix  ITGuy04 | 03/24/05
EVERYBODY: SHUT UP!  cicuta | 03/23/05
SO why don't you?  unstable1 | 03/23/05
I did  cicuta | 03/23/05
ppl here dont want to know the truth  jdahs@... | 03/23/05
Factoids are Factoids  John L. Ries | 03/23/05
re: EVERYBODY: SHUT UP!  segurajohn@... | 03/23/05
But most studies are funding by some entity other than  FilledOut | 03/27/05
Main Flaw!  Reverend MacFellow | 03/23/05
So, you're saying...  droby10 | 03/23/05
how bout these apples?  linuxoverwindows | 03/23/05
Re:how bout these apples?  school1012 | 03/23/05
How can this even be considered newsworthy???? ...  brianb_tdsc@... | 03/23/05
How about an independent Linux vs Win study - that would be newsworthy...  brianb_tdsc@... | 03/23/05
independant story  jguyp725@... | 03/23/05
Can't say I've noticed a differnce  voska | 03/23/05
Well said  K Anderson | 03/23/05
This is like asking the cat how the bird is feeling.  basilf@... | 03/23/05
Well Duh!  dinosaur_z | 03/23/05
Ho Humm! Again, the best "analysis" money can buy.  superbiskit@... | 03/23/05
"Microsoft-funded" it says it all...  mark_a_riley@... | 03/23/05
Message has been deleted.  itanalyst | 03/23/05
Maybe we should have Micrsoft fund a survey...  mark_a_riley@... | 03/23/05
MS bashing  Shift4SMS | 03/23/05
re: M$ bashing  GnarlyNome | 03/23/05
since the study is based for the most part on the number of days a flaw is  wessonjoe | 03/23/05
Linux riskier than Windows?  walterreads@... | 03/23/05
but the thing is, we'll never know how long it took M$ to really apply a  wessonjoe | 03/23/05
LOL!  golowenow | 03/23/05
linux? windows?  clint137 | 03/23/05
File this study along with  firerant | 03/23/05
Fundamentally flawed study.  agottschald | 03/23/05
A study by Linsux Sand Void revealed...  Expatriate US Geek | 03/23/05
hmm...  jdahs@... | 03/23/05
Yes, and according to Microsoft the Earth is flat,.  jackjack5 | 03/23/05
"....one of the most hated people"  Scrat | 03/26/05
Bill Gates is one of the most hated  matrixdomain | 03/27/05
In the dark recesses of your mind  RimaDog@... | 03/27/05
Who cares who funded this...  hughjanus | 03/23/05
Who cares???  johnlb2002 | 03/23/05
Adding more fuel to the fire...  rwilson_z | 03/23/05
Kind of what george ou  rwilson_z | 03/23/05
lol  jdahs@... | 03/23/05
Why post?  hughjanus | 03/23/05
Riskier?  d0ti5 | 03/23/05
MS propaganda on ZDNet  roger@... | 03/23/05
MS study finds Linux causes cancer LOL!  YuridaMan | 03/23/05
Some would be inclined to argue...  droby10 | 03/23/05
have many viruses?  r1kk1 | 03/23/05
Pimping Windows  gmerin | 03/23/05
Risk vs Common Sense  soulcircus | 03/23/05
Linux is worse, funded by Microsoft  jpenry_z | 03/23/05
oops  pizzathief | 03/23/05
I'm really getting tired of the BS  INetUsr | 03/23/05
Breaking News: M$ says windows is bestest!!!  supoman | 03/23/05
Well what did you expect fromM$  GnarlyNome | 03/23/05
Independent research? Paid for by Micro$oft?  meyer@... | 03/24/05
Too many years involved...  pkg90714@... | 03/24/05
Cumulative you boob  Hrothgar - PCLinuxOS User | 03/30/05
Who sponsored the study by unnamed researchers?  scott1329 | 03/24/05
Welcome to the club!  shenefeltg@... | 03/24/05
So you have some sort of imperical data that says  Laff | 03/24/05
Look, see and watch where Linux is now  matrixdomain | 03/24/05
It's so true, its so popular that it must be getting hacked daily  FilledOut | 03/24/05
Linux vs. Windows  johnnytech486 | 03/25/05
It's only true if Gartner says so  FilledOut | 03/27/05
??Linux riskier than Windows?? how?  kamowa | 03/31/05
opps  kamowa | 03/31/05

What do you think?

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and
advertisement
Click Here