Welcome | Sign In
ECommerceTimes.com
Applications

Homeland Security Moves to Harden Open-Source Software

Print Version
E-Mail Article
Reprints
Homeland Security Moves to Harden Open-Source Software

"DHS doesn't want to fund commercialization of something that's going to flop, so Symantec's job is to make sure that what we produce will actually make money and help the government and private industry," Stanford Professor Dawson Engler said.


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

The widespread adoption of open-source software by corporations and governments has raised some security concerns in the U.S. Department of Homeland Security (DHS), and the agency is responding.

It has funded a three-year grant reportedly worth US$1.24 million to -- among other things -- set up a daily auditing program of major open-source applications. The grant money will be divvied up among its recipients, Stanford University of Palo Alto, Calif. ($841,276), Coverity of San Francisco ($297,000), and Symantec (Nasdaq: SYMC) of Santa Monica, Calif. ($100,000).

"The DHS is realizing that more and more of our nation's critical software infrastructure is being run on top of open source," Coverity Vice President for Marketing and Business Development David Park told LinuxInsider.

"There's a feeling that there must be a hardening of these software projects to make them more reliable and secure," he said.

Killing the Bugs

Coverity's bug-zapping program, Prevent, will be used to conduct the daily audits called for in the grant and post them to a secure, restricted-access Web site for developers.

More than 30 programs will be audited by Coverity, including Apache, Firebird, Firefox, Gimp, Linux, MySQL, OpenSSH, OpenVPN and Samba.

In addition to paying for the daily vulnerability audits, the grant will be used to develop filesystem-checking tools for contribution to the open-source community, according to Professor Dawson Engler, who is administering Stanford's portion of the DHS money.

The tools will find bugs in storage systems, like RAID, that can crash and corrupt a system, he added.

Symantec's Role

Symantec could not be reached for comment on its role in utilization of the grant. However, the computer security firm will be working with Coverity "on market validation and some intelligence on what customers want and don't want in terms of security stuff," Engler told LinuxInsider.

"They will serve as a conduit for us to get a bunch of security trials at companies that may be happy to talk to Symantec but not to some random startup," he said.

"They will also get validation from the market," Engler added. "DHS doesn't want to fund commercialization of something that's going to flop, so Symantec's job is to make sure that what we produce will actually make money and help the government and private industry."

Some Community Members Miffed

Tools have been available to open-source developers for years to address flaws in the programs, according to Michael Gavin, a senior analyst for Forrester Research. "One thing that I've been surprised and disappointed by was that they were not used more broadly," he told LinuxInsider.

"Now that people are relying on open source, especially for so many servers, the Department of Homeland Security is stepping up and saying, 'we rely on them, and we need to make sure that they're more secure.'"

After news of the grant was made public, the DHS came under fire from some corners of the open-source world for its willingness to fund the search for bugs in open-source software despite its reluctance to pay for fixing the bugs exposed by Coverity's efforts.

"Open-source people have done a lot of stuff that's been good, and they haven't been paid for it," Gavin noted.

Questions Raised

"It is a little surprising that a private company is getting funded for this," Gavin continued. "If it had just gone to Stanford, that's one thing. But going to Stanford, Symantec and Coverity -- that's a little strange.

"It's not bad that somebody is putting money into it," he said. "To me, it's a little questionable as to how they decided who gets the money."

Addressing vulnerabilities in open-source software is a good thing, agreed Djenana Campara, CTO and chairperson of Klocwork, a software quality and security firm in Burlington, Mass.

"I'm really glad that Homeland Security is investing in these types of activities," she told LinuxInsider. "What I don't understand and can't comprehend is why they're funding the development of a particular vendor who is known in the quality defect detection space and now they're crossing into security -- so they're going to use this grant to develop their security offering."

However, Coverity has already established a presence in the security space, noted Jack Danahy, CTO and founder of Ounce Labs, a software quality and security company in Waltham, Mass.

"They focus on quality and security in a limited number of platforms versus a broader approach," he told LinuxInsider.

"They've been in security for a while," he added. "They're a credible player for the security problems that they find."

DHS could not be reached for comment.


Print Version E-Mail Article Reprints More by John P. Mello Jr.


Talkback: Join the Discussion.
Re: Homeland Security Moves to Harden Open-Source Software
Kagehi
Posted 2006-01-13
I can understand the fundimental paranoia about it, but this: "Coverity's bug-zapping ...

Related News Alerts

Symantec Activate Alert | Search Archives

More by John P. Mello Jr.

Learning the Way of the Snow Leopard
November 23, 2009
When confronted with a new piece of technology, some users will jump right in, but others may want to learn from an expert how to get the most out of it. Class On Demand puts 13 lessons onto a DVD that Mac greenhorns can use straight from their new computers. However, as many vendors operating in the Apple universe have found, one of their biggest rivals may turn out to be Apple itself.
VMware Fuses Performance With Convenience
November 16, 2009
Fusion 3.0, the latest virtualization app from VMware that lets Mac users run Windows alongside OS X, puts an emphasis on performance. VMware built it specifically to leverage the 64-bit capabilities of Snow Leopard with a new 64-bit native engine. Its Migration Assistant for Windows lets Mac switchers recreate their old Windows PC inside a Mac, file by file.
Mouse Meets Multi-Touch
November 09, 2009
Apple's latest peripheral, the Magic Mouse, takes the concept of multi-touch that the iPhone and iPod touch popularized and merges it with a button-free mouse. As one's mouse is a direct point of contact between human and machine, any changes made to it can be a divisive issue. Some users love the new abilities Magic Mouse brings to the table; others just can't stand the thing.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network