Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

New Tool Lets Enterprises Manage Security on Multiple Linux Servers

Trusted Computer Solutions readies software that can 'lock down' servers running Red Hat, CentOS, or Oracle Enterprise Linux

The good news about open source security tools is that they're cheap and don't require much administration. The bad news about open source security tools is that they're cheap and don't require much administration.

That's the problem faced by many computing environments that use a large number of Linux servers. The security tools available in the open source environment are easy to procure, but they don't offer a central method of handling administration across multiple servers.

Trusted Computer Solutions Inc. tomorrow will attempt to jump into this void with the introduction of Security Blanket 2.0 Enterprise Edition, an automated "system lock down" and security management tool for Linux operating systems that can manage all local and remote Linux servers from a centralized Web-based management console.

The idea is to make it easier for larger Linux environments, such as government and educational organizations, to do the "hardening" process required to meet security compliance requirements, says Jamie Adams, senior developer at TCS.

"This will help organizations lock everything down to make assessors happy," Adams says. "It helps you figure out what needs to be configured, and then it helps you do the configuration. Then it helps you enforce the policy, making sure all of your servers are configured consistently and all the patches are up to date."

Currently, the primary open source tool for security administration is Bastille, but Bastille can't configure multiple servers from a central location and doesn't always meet current standards for compliance. "There's no commercial entity working on it," Adams observes. "You're not always getting updates right away."

The Enterprise version enables administrators to easily group Linux servers, associate a lockdown profile with a group of servers, scan all servers within a group to determine compliance, and configure the server operating systems to the lockdown level of the chosen profile.

Security Blanket 2.0 Enterprise includes the security guidelines recommended by the Center for Internet Security (CIS), the Defense Information Security Agency (DISA) Security Technical Implementation Guides (STIGs), and select guidelines from the SANS Institute’s defined risks associated with Linux. It lets administrators group servers, select one of these industry lockdown profiles (or build their own), assess the state of the servers against the profile, and then automatically configure the operating systems to meet those profile guidelines, TCS says.

Automation might increase organizations' interest in server hardening, which many still don't do, said Forrester Research in a report issued last year.

"Although server hardening is a well-established practice, only [45 percent] of interviewees harden all of their servers, and [26 percent] left some Internet-facing servers unhardened," Forrester said. "Why? Perhaps because they feel they can't spare the time -- today, [53 percent] of systems administrators harden their servers manually."

Security Blanket Enterprise Edition starts at $3,000 for a console that supports up to 100 servers. Server licenses start at $198 per server.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • The Center for Internet Security (CIS)
  • Forrester Research Inc.
  • The SANS Institute
  • Trusted Computer Solutions Inc.

    Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    Zero-Factor Authentication: Owning Our Data
    Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
    44% of Security Threats Start in the Cloud
    Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
    Firms Improve Threat Detection but Face Increasingly Disruptive Attacks
    Robert Lemos, Contributing Writer,  2/20/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Current Issue
    6 Emerging Cyber Threats That Enterprises Face in 2020
    This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
    Flash Poll
    How Enterprises Are Developing and Maintaining Secure Applications
    How Enterprises Are Developing and Maintaining Secure Applications
    The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-9351
    PUBLISHED: 2020-02-23
    An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerConsoleOperations.jsp or /isomorphic/IDACall with malformed XML data in the _transaction parameter, the server replies with a verbose error showing where the application resides (the a...
    CVE-2020-9352
    PUBLISHED: 2020-02-23
    An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter.
    CVE-2020-9353
    PUBLISHED: 2020-02-23
    An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL is affected by unauthenticated Local File Inclusion via directory-traversal sequences in the elem XML ...
    CVE-2020-9354
    PUBLISHED: 2020-02-23
    An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite files via vectors involving an XML comment and /.. pat...
    CVE-2020-9355
    PUBLISHED: 2020-02-23
    danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.