Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

11/18/2008
06:22 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Secure OS Gets Highest NSA Rating, Goes Commercial

Unlike existing commercial OSes, Integrity OS is designed and certified to defend against sophisticated attacks

An operating system used in military fighter planes has raised the bar for system security as a new commercial offering.

After receiving the highest security rating by a National Security Agency (NSA)-run certification program, Green Hills Software has announced that its Integrity-178B operating system was certified as EAL6+ and that the company had spun off a subsidiary to market the OS to the private sector as well as government agencies.

"[EAL6+] is the highest [rating] in the world [given to an OS so far today]. This means that the OS was designed and certified to defend against well-funded and sophisticated attackers," says David Chandler, CEO of Integrity Global Security, the new Green Hills subsidiary.

Windows and Linux, meanwhile, are EAL 4+ certified, which means they can defend against "inadvertent and casual" security breach attempts, Chandler says. Integrity-178 B meets the rigorous Common Criteria Separation Kernel Protection Profile (SKPP) standard, which guarantees that malicious code can't corrupt or harm any other application running on the system.

"I'm delighted that they have accomplished this," said Stephen Hanna, co-chair of the Trusted Computing group and distinguished engineer with Juniper Networks, during his keynote at the CSI 2008 conference in National Harbor, Md., Tuesday. "This is serious security."

The OS, which was first deployed in the B1B bomber in 1997, today runs in military and commercial aircraft, including the F-16, F-22, and F-35 military jets, and the Airbus 380 and Boeing 787 airplanes. "It was developed for the highest level of security and reliability," Chandler says. "It's designed to provide a separation, so that what's happening in one area of the computer will not hurt the other part of the OS."

Popular operating systems, such as Windows, Linux, and MacOS, can run atop Integrity-178B, basically as virtual "guests" on the OS, while Integrity runs in hardware. Each operates in its own partition so that if one area is compromised, it can't spread to other areas of the system. "If a hacker got in past the firewall, intrusion detection system, and through Linux," he couldn't get anywhere else in the system, Chandler says.

The OS can run as the sole OS or on servers and clients running Windows, Linux, MacOS, Solaris, and VxWorks, as well as on Palm OS and Symbian PDA's.

Why go commercial now with the hardened OS? Integrity's Chandler says enterprises have been ready for "quite some time" for a more secure operating system. The system and its associated integration and consulting services are custom solutions, says Chandler, who declined to reveal pricing details for that reason.

But whether enterprises will have room in their budgets for hardening their OS environments is unclear as the global financial crisis worsens.

Chandler maintains that locking down the OS saves money for security in the long run. "There's an opportunity that this [solution] could be a cost savings for enterprises, with all that is spent on intrusion prevention" and other security tools and efforts, he says.

Meanwhile, Neil MacDonald, vice president and fellow at Gartner, says partitioning is key to ensuring the security of data and represents the foundation of Gartner's Adaptive Security Infrastructure vision. "Security software running on the same physical machine as the workloads and information it is protecting can't be unequivocally trusted without strong isolation, high assurance, and resiliency of the software," he says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
NSA Appoints Rob Joyce as Cyber Director
Dark Reading Staff 1/15/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: I like the old version of Google assistant much better.
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8567
PUBLISHED: 2021-01-21
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods.
CVE-2020-8568
PUBLISHED: 2021-01-21
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that conta...
CVE-2020-8569
PUBLISHED: 2021-01-21
Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, ...
CVE-2020-8570
PUBLISHED: 2021-01-21
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executi...
CVE-2020-8554
PUBLISHED: 2021-01-21
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typicall...