Linux developers hunt for kernel bugs

Linux developers have begun an ambitious project to identify security problems with the open source operating system before they trouble end users.

John Leyden

Linux developers have begun an ambitious project to identify security problems with the open source operating system before they trouble end users.

The Linux Kernel Auditing Project is an attempt to audit the Linux kernel for any security holes. The project also aims to educate Linux developers on how to write code securely and thereby stay ahead of crackers in creating a secure operating environment.

Advertisement

Bryan Paxton, who wrote the mission statement for the project, said it was time for a security audit of the Linux kernel and that the process would result in more secure operating system for end users.

"Certain proprietary operating systems sit around, and wait for a security bug to come to them and not go to bug themselves," said Paxton. "Linux kernel developers/hackers are down to earth and pretty logical people, and realise that Linux is not perfect, that a lot of the code they write, submit, and gets plugged into the kernel is not flawless, and more than likely could be improved for security reasons."

The audit will deal with current source code and will not develop additional patches nor add new functions, which might affect or disrupt other parts of the kernel.

Roy Hills, technical director of security testing firm NTA Monitor, praised the move and said it made sense to separate the auditing and fixing functions involved in making an operating system secure.

"Open source operating systems are subject to bugs similar to those that affect proprietary systems, but people in the open source community seem to react quicker to things and are more open about it," he added.

OpenBSD, another Unix-like open source operating system, has been subject to an ongoing security audit since 1996.

Matthew Pemble, former security specialist in the Royal Navy and now at integrator IS Integration, said: "A formal code review, which this project is aiming for, would be a huge undertaking for a big operating system.

"Microsoft operating systems have not been desperately well tested, and because of the ubiquitous nature of that operating system that can have significant consequences."

The Linux Kernel Auditing Project is being undertaken by groups of Linux enthusiasts and developers who will work via a mailing list. The suggested kernels to be audited are 2.0.x kernel series, 2.2.x kernel series and the 2.3.x/2.4.x kernel series.

To subscribe to the project's mailing list, send a message with the body text 'subscribe kernel-audit' to majordomo@nl.linux.org

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Final test release of Linux is posted

Linux creator Linus Torvalds has posted the near-final release of the Linux 2.4 kernel to the kernel.org website.

Linux delays won't hit developers

The delay of the next version of the Linux kernel is likely to shake user confidence in the operating system despite having little effect on software development.

European firms getting security wrong

Security has finally become an item on the corporate agenda but many companies are taking the wrong approach to addressing the issue, according to research by IDC.

Red Hat tunes Linux for clustered servers

Red Hat has launched a version of the Linux operating system for use in clustered server environments.

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

shackleton

Content management tools "barely being used"

Open Text chief predicts more consolidation in ECM market

Scott Totzke

Interview: Scott Totzke, VP global security, RIM

We ask the BlackBerry maker's head of security what CIOs...

Apple Magic Mouse

Review: Apple Magic Mouse

Multi-touch makes an appearance on Apple's latest mouse

clouds

Industry needs to come clean on cloud security

Trend Micro CTO warns of widespread data theft

Primary Navigation