SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Enterprise Business Applications >> Open Source and Linux

Why buy commercial products when there are open-source security tools?

Why buy commercial products when there are open-source security tools?

By:  Ellen Messmer  On: 20 Mar 2007 For: Network World (U.S.) Creator

Open source security tools abound, so take advantage of them and avoid paying for commercial products if open source fits your needs. That was the message from Matthew Luallen, president of consulting firm Sph3r3, who spoke at Monday's InfoSec Conference.

COMMENT ON THIS ARTICLE

Open source security tools abound, so take advantage of them and avoid paying for commercial products if open source fits your needs. That was the message from Matthew Luallen, president of consulting firm Sph3r3, who spoke at Monday's InfoSec Conference.

Pointing to two Web sites, Freshmeat.net and Sourceforge.net , as central repositories to find open source software and information, Luallen told InfoSec attendees about the rich supply of vulnerability scanners, authentication software, penetration testing tools, antispam, intrusion-detection systems and more that exist as open source or freeware.

"The WiKiD Strong Authentication Server is a two-factor authentication server ," said Luallen, referencing ones he thought among the most useful . Among other great security tools there for the asking are SpamAssassin, which can identify spam, Splunk for log analysis, NTop for anomaly detection, TrueCrypt for encrypting data at rest, and the penetration-testing tool BackTrack. He said all are examples of useful security tools that companies should consider securing enterprise networks.

"Technically, the Splunk Log Analysis is not open source but it's freeware, Luallen said. "It can interpret log files from almost any application out there. We have to know what's going on in our environment, whether it's Linux, Windows, switches, routers, whatever you will." He added Splunk has become particularly useful because it can make use of the SANS Institute Top 5 log-analysis scripts.

Luallen said he had a few caveats about using open source and freeware tools in enterprises, however. These open source tools might be bought or their makers could abandon them. In addition, there's a risk that this easily available software could have a backdoor or malware in it, inserted either deliberately or because a hacker compromised it. "Anything you download off the Internet could have a backdoor or a 'phone home' associated with it," Luallen cautioned. He added some tools are also going to require a bit of programming skill to really take advantage of them.

Some of the better-known tools, such as Snort for intrusion detection and Nessus for vulnerability scanning, are "becoming more closed source as time goes on," he pointed out, and their originators either decide to focus more on commercial products or the tools are bought by a software vendor. Trend Micro, for example, recently bought the antispyware HijackThis from its Netherlands-based creator, but intends to keep it freeware for now.


Sign up for our Newsletters












Print |  Views: 615   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Ellen Messmer Ellen Messmer is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Enterprises concerned about open source support: Forrester
Enterprises concerned about open source support: ForresterConcerns around support trump intellectual property and security issues, according to a Forrester survey of European firms actively using open source
Virtual networking practices up for debate
Virtual networking practices up for debateThe virtual network begins where the physical network ends at the virtualization host. The network adapters in the physical host are bridged to the virtualization layer. What happens next depends on the virtualization host in use
Eight steps to lightning-fast Web applications
Eight steps to lightning-fast Web applicationsAccelerator software can now do things like cache content so servers don’t have to do it, compress content on the fly and rewrite headers to improve security. Get moving with these strategies
Ontario Linux Fest Starts Soon
by jason w. eckertthe second annual ontario linux fest is a great opportunity to network with other it professionals and attend one of many workshops to learn about open source solutions. it will be held at the days hotel and conference centre in toronto on saturday october 25th. you can view the workshops available as well as register online at
blog comments powered by Disqus