Open Source Hardening Project
Home > Security Definitions - Open Source Hardening Project
SearchSecurity.com Definitions (Powered by WhatIs.com)
EMAIL THIS
LOOK UP TECH TERMS Powered by: WhatIs.com
Search listings for thousands of IT terms:
Browse tech terms alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #

Open Source Hardening Project



Word of the Day
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


DEFINITION - The Open Source Hardening Project is an initiative of the United States Department of Homeland Security, created to improve the security of open source code. Because the infrastructure of the Internet, financial institutions and many other critcal systems in the U.S. run on open source software, the security of these applications is crucial.

Participants in the project were given grants from Homeland Security: Stanford University ($841,276), Coverity ($297,000) and Symantec ($100,000). Stanford and Coverity collaboratively developed Prevent, an automated system for scanning submissions from open source programmers to popular projects. Vulnerabilities found are documented in a database for the development community. Coverity employs a rating system called the "Scan Ladder" to rank projects on a progressive track to security certification. Symantec's role is to test out Scan in the proprietary software that they work with and to provide security expertise.

Homeland Security lists the Department's priorities in their National Cyberspace Strategy document:

  • Identifying and remediating existing vulnerabilities.
  • Developing systems with fewer vulnerabilities and assessing emerging technologies for vulnerabilities.
They list sub-priorities as:
  • Securing the mechanisms of the Internet.
  • Improving the security and resilience of key Internet protocols.
  • Reducing and remediating software vulnerabilities.
  • Assessing and securing emerging systems.

In the project's first year, 50 projects scanned yielded over 6000 vulnerabilities, which were fixed by open source developers using Prevent's results. In the second year there were 150 projects scanned. By March 2008, 7,826 defects had been fixed in 267 projects. Higher ranked projects that fix the most vulnerabilities get deeper access to Prevent's features.

The project, formally known as the Vulnerability Discovery and Remediation, Open Source Hardening Project, launched in March 2006 and is scheduled to run for three years, with a budget of 1.24 million dollars. Some of the better-known projects scanned include Apache, Firefox, GIMP and a number of forms of Linux and BSD.

LAST UPDATED: 08 Apr 2008

Read more about Open Source Hardening Project:
- News.com reports on the initiation of the Open Source Hardening Project.
- SearchSecurity.com describes how the Open Source Hardening Project is discovering flaws.
- This PDF document evaluates Prevent.
- Coverity offers a FAQ list about Scan.


Do you have something to add to this definition? Let us know.
Send your comments to techterms@whatis.com


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Using Nessus Attack Scripting Language (NASL) to find application vulnerabilities
In this new addition to our Nessus 3 Tutorial, Mike Chapple provides examples of NASL scripts that can find known vulnerabilities in your customized...
What are best practices for creating an IDS and maintaining a signature database?
Mike Chapple offers an alternative to creating an intrusion detection system as well as advice on maintaining a signature database.
How to install and configure Nessus
This tip introduces Nessus, and explains how to install Nessus and configure deployment.

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Back Orifice  (SearchSecurity.com)
Blowfish  (SearchSecurity.com)


TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts