Slashdot Mirror


Secure OS Gets Highest NSA Rating, Goes Commercial

ancientribe writes "A hardened operating system used in the B1B bomber and other military aircraft has now been released commercially, after receiving the highest security rating by a National Security Agency-run certification program. Green Hills Software's Integrity-178B operating system was certified as EAL6+, which means that it can defend against well-funded and sophisticated attackers." The company is not saying how much the OS would cost a potential customer: "The system and its associated integration and consulting services are custom solutions." Both Windows and Linux are EAL 4+ certified, which means they can defend against "inadvertent and casual" security breach attempts.

62 of 352 comments (clear)

  1. Let the Testing begin... by sbenson · · Score: 5, Insightful

    Now let people who don't have financial ties test it.

    1. Re:Let the Testing begin... by Verdatum · · Score: 5, Informative

      The financial ties involved in EAL evalution are pretty loose at best. I'm more familiar with FIPS and Orange Book evaluation, but assuming the processes are similar, evaluation is done a an independent third party organization; usually as a result of a requirement stated in a government contract. There is not much in the way of monetary incentive for the evaluation group to rate a product any higher than it deserves to be.

      That being said, I don't believe EAL6+ requires any additional vulnerability testing beyond that of than EAL5+; it is mostly just a stricter evaluation/review of the soundness of the OS design.

    2. Re:Let the Testing begin... by sbenson · · Score: 5, Insightful

      If it is Internet facing, it's an open test bed.

    3. Re:Let the Testing begin... by Isao · · Score: 5, Informative
      Ok, here are some real facts about how this works.

      Under the Common Criteria (CC), people with financial ties create the product. They (or another sponsor who wants the product evaluated) pay an independent lab (CCTL) to evaluate it. Labs are certified by NIAP, a partnership of NIST and the NSA Information Assurance directorate. (The NSA has two main parts, the other is Signals Intelligence.) The independent lab evaluation is overseen by a Validation team employed by the government, who reviews the process and results of every evaluation, including all vendor evidence, before it is certified. The Validators also oversee the labs for proper execution of the CC. Once it passes all these reviews successfully it is certified.

      Certifications are tiered by Evaluation Assurance Levels (EALs), from 1 to 7. Generally, the higher the EAL, the greater confidence there is in the vendor claims. This is NOT the same as being more secure!

      The way to use these certified products is to select a product family (say firewalls), and review at a minimum two documents: The Security Target (ST) and Validation Report (VR). The ST is written by the vendor or sponsor, and basically contains the security claims they're making for the product, and how they expect the product to be used. The Validation Report describes how those claims were evaluated, and what notable things the Validation team observed during the evaluation. After reading both of these documents (usually not more than 100 pages - pretty short for 1-2 years of work) you can determine if the product can be used in its certified configuration in your environment.

      Check out some interesting operating systems, like Windows XP, Mac OS X, or one of the Linux's.

      It's certainly not perfect, but it's better than what we had.

  2. n/t by KasperMeerts · · Score: 5, Insightful

    I'm sorry if I take a test that gives Windows and Linux the same security rating not very seriously.
    Also, how can they test this? The only way to properly test something like this is to let it out in the wild for a decade or two. That's not something you can imitate in a testing room.

    --
    As long as there are slaughterhouses, there will be battlefields.
    1. Re:n/t by characterZer0 · · Score: 5, Informative

      EAL does not mean what you think it does.

      http://en.wikipedia.org/wiki/Evaluation_Assurance_Level

      --
      Go green: turn off your refrigerator.
    2. Re:n/t by moderatorrater · · Score: 5, Interesting

      Source code audits with automated scripts that attack every port and every program checking for buffer overflows or other avenues of attack. It would require a lot of work, but it makes sense that the NSA would put in a lot of work to explore these operating systems, both to know how to secure against attack and to know how to pull off an attack against another country. The real question is, how much do you trust this OS not to have an NSA back door?

    3. Re:n/t by blhack · · Score: 5, Insightful

      Also, how can they test this? The only way to properly test something like this is to let it out in the wild for a decade or two. That's not something you can imitate in a testing room.

      You forget the the NSA pretty much recruits the best and brightest hackers that the world has to offer. Their policy of "we don't have a budget" and the oppurtunity to work on the absolute cutting edge (and actually see it put to use) is pretty much the most kickass thing that you can offer somebody who has a passion for knowledge.

      --
      NewslilySocial News. No lolcats allowed.
    4. Re:n/t by thermian · · Score: 4, Insightful

      I imagine they see having the source code available as a negative for Linux simply because it gives would be attackers much more information about the system than is otherwise available.

      That theory is one touted by commercial OS vendors, and its been thoroughly disproved. Availability or otherwise of source code has no effect on the hardness of your OS. If anything having it available is even safer, because its a heck of a lot easier for people to point at a problem bit of code and say 'fix that bit now'.

      What causes the problem is non rigorous OS design. Hiding the source won't help you protect your clients from a design flaw which allows them to be attacked.

      The OS in question here however is most likely quite rigorously designed, and won't have a lot of the bloat that causes desktop OSs so many problems.

      --
      A learning experience is one of those things that say, 'You know that thing you just did? Don't do that.' - D. Adams
    5. Re:n/t by Zackbass · · Score: 2

      Then why are they recruiting some of the best mathematicians I know?

      --
      You gotta find first gear in your giant robot car
    6. Re:n/t by CaptainPatent · · Score: 5, Insightful
      Indeed, I was looking at that too and some interesting points from the wiki article:

      To achieve a particular EAL, the computer system must meet specific assurance requirements. Most of these requirements involve design documentation, design analysis, functional testing, or penetration testing. The higher EALs involve more detailed documentation, analysis, and testing than the lower ones. Achieving a higher EAL certification generally costs more money and takes more time than achieving a lower one. The EAL number assigned to a certified system indicates that the system completed all requirements for that level.
      [...]
      Technically speaking, a higher EAL means nothing more, or less, than that the evaluation completed a more stringent set of quality assurance requirements. It is often assumed that a system that achieves a higher EAL will provide its security features more reliably (and the required third-party analysis and testing performed by security experts is reasonable evidence in this direction), but there is little or no published evidence to support that assumption.

      So basically it costs money to get EAL verified, and the farther up the scale you go, the more money it costs to run the testing. So even if a Linux distro wanted to be verified at a higher level - who's going to fork over the dough?

      Additionally this seems to be a hired method of testing and bug report/fixing. Just because they fix the bugs found at one "level" of testing does not mean there aren't missed holes. Additionally it doesn't mean that a well written piece of software isn't capable of a higher rating with little or no fixes (like the Linux kernel probably is.) It is impressive that Integrity-178B achieved the EAL-6+ rating because it has definitely been put through its paces... and due to the way it was designed it probably has very few holes in it, but EAL should definitely not be the end-all be-all judge of OS quality.

      --
      Well, back to rejecting software patent applications.
    7. Re:n/t by thedonger · · Score: 2, Funny

      That is, "there," not "their." Don't I feel stoopid.

      --
      Help fight poverty: Punch a poor person.
    8. Re:n/t by betterunixthanunix · · Score: 5, Interesting

      Actually, the security of a system should not depend on hiding the operating details of the system. The EAL levels are based on things like audit logs, privilege separation, the ability to kick a user off the system and kill all their processes, etc. The availability of the source is neither a positive nor a negative on EAL ratings.

      --
      Palm trees and 8
    9. Re:n/t by the_other_chewey · · Score: 5, Funny

      So basically it costs money to get EAL verified, and the farther up the scale you go, the more money it costs to run the testing.

      Is Scientology somehow involved in this?

    10. Re:n/t by lanterndog · · Score: 4, Interesting

      Yeah... I majored in pure math (e.g. abstract, theoretical stuff) in college. I was good. The NSA was all over me. I didn't accept, obviously (I wouldn't be able to admit this if I had. :) They recruit lots and lots of math people. Very few CS people (I double-majored in math and CS. Google and MS tried to recruit me through CS). However, I will get flamed to the end of the earth for this, but it's my experience: Mathematicians are insanely more intelligent than CSers. That, and cryptography (which is why the NSA exists) has much more to do with mathematics (Algebra and Number Theory especially) than it does with programming or OS design.

    11. Re:n/t by Anonymous Coward · · Score: 5, Funny

      Don't I feel stoopid.

      Especially so after you forgot to check 'Post Anonymously' the second time around...

    12. Re:n/t by Anonymous Coward · · Score: 5, Informative

      You apparently did not read the wikipedia article through. The reason that Windows and Linux (distributions) achieve EAL-4 rating is because "EAL4 is the highest level at which it is likely to be economically feasible to retrofit to an existing product line."

      Furthermore, "Commercial operating systems that provide conventional, user-based security features are typically evaluated at EAL4."

      Higher levels require some sort of formal methods use in the design and testing. This is very unlikely to ever happen for Linux (it is virtually impossible to create a formal design retroactively; either it does not correspond to the system or it is just as complex as the system).

      For this reason, Linux will probably never get any higher. Windows may just get higher, because it has a completely new security model and kernel, which are likely able to get EAL-6 grading in time.

    13. Re:n/t by orclevegam · · Score: 4, Insightful

      Cryptography yes, security no. Although cryptography is a very important tool in designing a secure OS, it's not the only one, and probably not even the most important one. Likewise for software in general. Cryptography is important for communications, and data protection which makes it important for communications between programs, and storage of programs, but actually ensuring the integrity of the system or application has a lot more to do with CS than it does Math. Both math and CS students can be equally smart, but in different ways. The math students will tend to be good at number crunching and abstract thinking, particularly in regard to projecting problems into various spaces where they can be solved using various functions. The CS students are going to tend towards a more systematic view of things in which they break problems down into sub-components without losing track of the larger picture and the way the various pieces interlock and interact with each other. You most likely perceive the math students as being "more intelligent" because you yourself are more inclined to the mathematical way of thinking about things.

      When the NSA was first created the primary concern with regards to security was a combination of mathematical and physical problems. Mathematics in the form of encrypted communications, and physical in the form of ensuring that the people and/or documents that contained sensitive information and the devices used to cypher them were properly secured. With the rise of the internet and the switch to an increasingly interconnected infrastructure software security has emerged as a factor now. It no longer matters how good the encryption is between your two programs if the OS their running on can be compromised and the data scraped as the application decodes it (or better yet the encryption key itself). As such even though the NSA started as an organization specializing in primarily cryptographic systems it must expand to include software and hardware security as well.

      --
      Curiosity was framed, Ignorance killed the cat.
    14. Re:n/t by drsmithy · · Score: 3, Interesting

      So basically it costs money to get EAL verified, and the farther up the scale you go, the more money it costs to run the testing. So even if a Linux distro wanted to be verified at a higher level - who's going to fork over the dough?

      Commercial Linux vendors like Red Hat, SuSe and IBM.

      Certifications like EAL tell you about the technical capabilities of an OS. They don't tell you anything about how competently said OS will be used.

    15. Re:n/t by Kjella · · Score: 5, Insightful

      So basically it costs money to get EAL verified, and the farther up the scale you go, the more money it costs to run the testing.

      Uh, yes? The more specific the documentation, the more work has to be done to verify it. I'm not sure how many million LOCs are in the Linux kernel but if I had to go through EAL6+ semi-formal proofs for all of them I'd charge a bundle too. Are you really trying to imply that NSA issue this sham certification because they're short on funding? Stop trying to pretend that all the "experimental support" that goes into Linux could or should pass certification, because it damn well shouldn't. Certainly not on based on a casual "it's probably capable" that's quite frankly pulled out of your nethers with no documentation to back it up. Here for example are THREE security exploits in the kernel in the last two months:

      1 Linux Kernel VDSO Unspecified Privilege Escalation Vulnerability (Vulnerabilities) Rank: 820
      Last modified on: 2008-11-04 00:00:00 MST
      URL: http://www.securityfocus.com/bid/32099
      2 Linux Kernel LDT Selector Local Privilege Escalation and Denial of Service Vulnerability (Vulnerabilities) Rank: 820
      Last modified on: 2008-10-03 00:00:00 MDT
      URL: http://www.securityfocus.com/bid/31565
      3 Linux Kernel 'generic_file_splice_write()' Local Privilege Escalation Vulnerability (Vulnerabilities) Rank: 820
      Last modified on: 2008-10-03 00:00:00 MDT
      URL: http://www.securityfocus.com/bid/31567

      Don't get me wrong, Linux is a great system and all but I wouldn't want to nuclear launch control on it, sorry.

      --
      Live today, because you never know what tomorrow brings
    16. Re:n/t by InlawBiker · · Score: 2, Interesting

      Nokia IPSO, which is certified for Check Point FW-1 and VPN-1 and is based on BSD, is also EAL4.

         

    17. Re:n/t by ozbird · · Score: 3, Funny

      Mathematicians are insane.

      Fixed that for you.

      Admittedly, mathematicians can formally prove they are more intelligent the CSers, but nobody except another mathematician could a) understand the proof, and b) give a shit.

    18. Re:n/t by AvitarX · · Score: 2, Informative

      Isn't that what compile yourself means?

      He/She didn't say run the compiler yourself.

      --
      Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
    19. Re:n/t by conspirator57 · · Score: 3, Informative

      kind of, but not really. The higher EAL levels require things like proofs on your enforcement algorithms in the context of the machine (CPU feature set) it runs on. There are a lot of musty corner cases where user-based security fails. Thus it is impractical to retrofit existing OSes that rely on user-based security, because the security methods have fatal design flaws.

      as far as practicality, consider denial of service attacks using the confused deputy problem. Linux, like windows, is full of mutexes and spinlocks. The answer is priority inheritance, and even that is only a partial answer.

      --
      "If still these truths be held to be
      Self evident."
      -Edna St. Vincent Millay
    20. Re:n/t by orclevegam · · Score: 3, Insightful

      Having working with the OS in question and directly with the NSA on getting our own OS certified (which we decided was too expensive in the end, and wound up throwing it away to use Integrity-178B)....

      NSA does employ a sizeable group of mathemeticians in the area of security now as well. They've invested a lot of time in money in mathematical models for proving security, namely from the vantage point of possible combinations of system states, and how to minimize those into a human-testable number of states.

      Yes, I've seen some of the work that's been done on trying to create a OS that can be mathematically proven to be secure, but I just don't buy it. Sure you can use some set theory and various other things to try to show how mathematically the system is bounded within the secure states, but all of that goes out the window once you move beyond a non-trivial set of functionality, and completely ignores the human side of the equation (which is the most important part, if the system makes it hard on the user to remain secure, then the user won't use the system the way it's meant). I also wasn't saying that mathematicians have no place in software security, or that they aren't useful, just that a mathematician isn't necessarily the best (or even good) choice for designing a OS.

      Computer security is equal parts software, hardware, interface, and user training. Ignore any of those and you've just introduced your weak link in the system (usually the user and/or interface which go hand in hand). Hardware is only really an issue of you're trying to secure against a threat with physical access, which any halfway competent security professional can tell you is a stalling tactic at best. Software is critical to prevent things like buffer overflow attacks, but can be tested automatically with a good degree of accuracy. Interface and user training are really the linchpins of security. A good interface is a must in order to allow the user to make informed decisions concerning how trustworthy the system in question is, and proper training is important to allow the user to properly interpret the information they're receiving from the interface and to learn to spot subtle signs of problems.

      Of course, in a specialized environment like a B2, or highly secured and hardened systems like no doubt the NSA uses the problem can be reduced in scope as to be nearly fully encompassed by a mathematical state model, but in so doing you massively limit the capability of the underlying system. In essence you take a general purpose system (computer) and reduce it's functionality to one specific task in order to be assured of it performing that single task in a easily controlled fashion. Although this is fine for the highly specialized tasks the NSA puts these systems to it would never work in a general purpose system used by end consumers and even most businesses. Once you go down that route, you might as well just use an embedded device as you've already lost the greatest advantage a PC has which is generalized functionality.

      --
      Curiosity was framed, Ignorance killed the cat.
    21. Re:n/t by v1 · · Score: 2, Insightful

      what it means is that if you have a higher EAL number, it means you definitely have more money, and possibly are more secure.

      --
      I work for the Department of Redundancy Department.
    22. Re:n/t by Atario · · Score: 3, Funny

      Higher levels require some sort of formal methods use in the design and testing. This is very unlikely to ever happen for Linux (it is virtually impossible to create a formal design retroactively; either it does not correspond to the system or it is just as complex as the system).

      No problem.

      1. Create black-box-style formal spec of Linux
      2. Rebuild Linux from scratch using only the specs

      Easy!

      --
      "A great democracy must be progressive or it will soon cease to be a great democracy." --Theodore Roosevelt
  3. Two steps from the highest, actually by moderatorrater · · Score: 4, Funny

    EAL7+ means that it can defend against well-funded and sophisticated attacks and doesn't have an NSA backdoor built into it. EAL8 is exactly like EAL7+, only it can do it while getting slashdotted.

    1. Re:Two steps from the highest, actually by jbeaupre · · Score: 5, Funny

      EAL9+ means it autonomously retaliates against the attacker's system.
      EAL10+ means it autonomously retaliates against the attacker.

      --
      The world is made by those who show up for the job.
    2. Re:Two steps from the highest, actually by Sponge+Bath · · Score: 3, Funny

      My computer goes to EAL11!

      The power of God blazes out of the box to melt the faces and explode the heads of intruders,
      just like in Raiders of the Lost Mainframe.

    3. Re:Two steps from the highest, actually by Anarke_Incarnate · · Score: 5, Funny

      EAL11+ means it goes to eleven. The others they go to 10, but this one goes to 11, so if you need that extra.....push off the cliff....

    4. Re:Two steps from the highest, actually by Kadmos · · Score: 2, Funny

      EAL12+ means it can drink your milkshake.

  4. lols by negRo_slim · · Score: 4, Informative

    A hardened operating system used in the B1B bomber and other military aircraft has now been released commercially

    B1 Accidents, OS Homepage, More Wikipedia!

    --
    On the Oregon Cost born and raised, On the beach is where I spent most of my days
    1. Re:lols by db32 · · Score: 4, Insightful

      I blame all of my hardware problems on software too...

      Seriously, going through that list I see. Fire, lots of fires. Two instances of computer failure due to faulty hardware. A few landing gear hardware problems. A dash of pilot error or otherwise bad luck. And a rather unfortunate bird strike on a weak section of a wing (that was later redesigned because of this event IIRC).

      I am curious as to what you are trying to insinuate by linking to crashes due to these issues next to the software....

      --
      The only change I can believe in is what I find in my couch cushions.
  5. So why can't Windows and Linux do this? by Van+Cutter+Romney · · Score: 2, Interesting

    What's preventing Microsoft and open source world from understanding these "sophisticated" attacks and hardening their respective operating systems against them?

    --
    Help a man when he is in trouble and he will remember you when he is in trouble again.
    1. Re:So why can't Windows and Linux do this? by eddy · · Score: 2, Insightful

      The fact that both a windows installation and most linux dists need to be useful for the common folk, you know, with security no-nos such ethernet and maybe even USB support. And no, hotgluing ports doesn't cut it.

      Look, it'd be perfectly feasible to push Windows or GNU/Linux through a higher certification, but someone has got to pay for it and the market is infinitesimal.

      --
      Belief is the currency of delusion.
    2. Re:So why can't Windows and Linux do this? by Legion_SB · · Score: 2, Insightful

      In the big picture, there's a distinct trade-off between security and usability.

      That doesn't mean that, in the small picture, every security improvement comes at the cost of usability. But when you're talking big picture, to get the kind of security you're talking about, you have to rethink what it means to use a computer/OS/etc. Things you currently take for granted (like, as someone else said, plugging a USB device in) become "holes" that have to be closed.

      --
      'a';DROP TABLE users; SELECT * FROM DATA WHERE name LIKE '%'... if you're reading this, it didn't work.
  6. Worse than Dell with the Windows tax by Anonymous Coward · · Score: 5, Funny

    When you order a B1B, you pay for the Integrity-178B license even if you later install a copy of Linux For Strategic Bombers.

    1. Re:Worse than Dell with the Windows tax by Anonymous Coward · · Score: 2, Funny

      When you order a B1B, you pay for the Integrity-178B license even if you later install a copy of Linux For Strategic Bombers.

      Please don't run Linux For Strategic Bombers. The head maintainer is a well-known a**hole, for years he's refused to accept patches for longstanding bugs, and he's changed the license to prevent 3rd parties from distributing modified versions.

      The bombing community has created a new fork of the project starting from the last Free version, called "Bombastic". It's already capable of handling 80% of mission requirements, and version 1.0 should be released in the near future. Please encourage all of your squadrons to use this truly Free alternative instead.

    2. Re:Worse than Dell with the Windows tax by rrohbeck · · Score: 3, Funny

      When you order a B1B, you pay for the Integrity-178B license even if you later install a copy of Linux For Strategic Bombers.

      Aah, I always wondered what LSB stands for.

  7. lower that 4+ by internerdj · · Score: 5, Funny

    Inadvertant and Casual attempts?
    Oops. I tripped over my computer and hacked your system. Sorry.

    1. Re:lower that 4+ by CorporateSuit · · Score: 3, Funny

      "I hacked you? Sorry mate, I was just trying to play Solitaire"

      Looks like we're lucky this time. Last kid that accidently played videogames with our system chose Global Thermonuclear War!

      --
      I am the richest astronaut ever to win the superbowl.
  8. Unfortunately, probably a niche product at best by 93+Escort+Wagon · · Score: 3, Insightful

    It seems like in the OS battle between security and convenience, convenience wins every time. I see Windows everywhere - at the bank, on hospital equipment and at doctors' offices, on ATMs... not to rant specifically against Windows; but it shows up a lot of places where I think we'd be much better served if the company had gone to the time and expense of developing a custom solution. Really, why should Windows be running on an X-Ray machine or an electrical power plant console?

    --
    #DeleteChrome
  9. A tad careless? by Zathain+Sicarius · · Score: 2, Insightful

    Isn't releasing this OS a little careless? Part of the reason it's so secure is because only the military has its hands on it. If you go around selling it, I'm sure someone will buy it just to poke around and find each and every hole in its security.

  10. "Linux" is not certified for anything by crush · · Score: 5, Insightful

    A couple of specific distros on specific hardware have received EAL4+ certification: RHEL5 (on 12 or so different platforms) and SLES9 on IBM eServer spring to mind. I'm fairly sure that no other GNU/Linux distributions have received such certification and it makes absolutely no sense to talk about "Linux" being certified for anything.
    This is not just nit-picking about GNU/Linux vs Linux as the name: it's a case where it's actually very important to be aware that specific versions of specific programs with specific configuration files have been tested and found not to fail in particular ways.

  11. The Protection Profile and Validation Report by jea6 · · Score: 3, Informative

    The Protection Profile and Validation Report can be downloaded at http://www.niap-ccevs.org/cc-scheme/pp/id/pp_skpp_hr_v1.03.

    The Security Target and Validation Report can be downloaded at http://www.niap-ccevs.org/cc-scheme/st/vid10119/.

    --

    sarchasm: The gulf between the author of sarcastic wit and the person who doesn't get it.
  12. "Both Windows and Linux are EAL 4+ certified" by whoever57 · · Score: 3, Informative

    Is this really a true statement? According to Wikipedia, only Windows 2000, SP3 is EAL4 certified. Since this is an obsolete and unsupported release (Win2k SP4 is still supported), is it correct to say that "Windows..[is] EAL 4+ certified"?

    It would be more accurate to say either: "Windows 2000, SP3 is EAL4 certified" or "Windows used to be EAL4 certified".

    --
    The real "Libtards" are the Libertarians!
  13. Article misleads about EAL6 by epdp14 · · Score: 4, Informative

    EAL6 is NOT the highest rating given by the NSA. EAL7 is. EAL7 has been awarded to one product (The Tenix Interactive Link Data Diode Device). Source: http://en.wikipedia.org/wiki/Evaluation_Assurance_Level

    1. Re:Article misleads about EAL6 by oGMo · · Score: 2, Funny

      Actually it's EAL8. But you can't know about it, because it's insecure. Products that qualify for EAL8 can be neither confirmed nor denied, because if you knew about them, they wouldn't qualify. Those developers that make it are EAL8-ed.

      ;-)

      --

      Don't think of it as a flame---it's more like an argument that does 3d6 fire damage

  14. You don't know how your walls can be breached by wintermute42 · · Score: 4, Insightful

    The nature of computer system penetration (hacking) is that it takes a great deal of time and patience. The attacker will put a lot of effort into learning everything they can about the system and then more time in probing possible vulnerabilities.

    Linux and Unix systems in general have a better underlying security model than Windows (e.g., the way root/administrator vs. user is handled). Unix architectures also had years of students attacking them (back before this was a serious crime). However, if those of us who are Linux fans are honest we know that the reason we don't have to worry as much about Linux attacks is that hackers target Windows because it is more pervasive.

    The Greenhills operating system has never been exposed to a large group of people who are willing to spend a lot of time penetrating it. The idea that you can just label a system as secure seems questionable. You always get attacked via means that you didn't expect. What they're really saying is that the system implements a security model that they believe to be secure. But B1 bombers are not placed on the Internet protecting large amounts of money, so they are unlikely to attract hackers.

  15. OpenBSD? by 1053r · · Score: 2, Insightful

    Does anybody know if OpenBSD (or any *BSD for that matter) has ever received a rating? Or at least, what it would probably rate if it were to receive a rating? I would suspect that it would rate at least with Linux or perhaps one higher, seeing as their slogan is "only two remote holes in the default install in over a decade."

  16. Re:Anonymous Coward by CorporateSuit · · Score: 4, Funny

    As much faith as I have in the NSA's security abilities, does anyone have any idea what criteria they were using exactly? Any in-depth results they've made public, preferably?

    It's an aggregate result of how many social security numbers B1 bombers have lost over the last 10 years divided by how many B1 bombers, with the software installed, have been stolen out of government offices or left behind in taxi cabs.

    --
    I am the richest astronaut ever to win the superbowl.
  17. Re:Anonymous Coward by bl8n8r · · Score: 2, Funny

    NSA E.A. Testing Criteria
    ---
    EAL0 $1,000,000
    EAL1 $1,000,000
    EAL2 $2,000,000
    EAL3 $3,000,000
    EAL4 $4,000,000
    EAL5 $5,000,000
    EAL6 $6,000,000
    EAL7+ Call for quote.

    --
    boycott slashdot February 10th - 17th check out: altSlashdot.org
  18. This is an RTOS, not a general purpose OS by EmbeddedJanitor · · Score: 2, Insightful
    GreenHills make RTOS solutions for embedded use etc. The emphasis is on robustness and security over features. It is a painstaking process of testing and verification to add features.

    Sure, in theory, Windows and Linux could attain these levels of security but in practice Windows and Linux favor adding features and capabilities. Compromises have to be made to get stuff out in an acceptable timeframe.

    --
    Engineering is the art of compromise.
  19. I think you missed the point by MikeRT · · Score: 2, Insightful

    The point here is that it really does make good use of security through obscurity here. By being a product that is sold only to customers that work in classified environments, it has an inherent advantage in that almost no one outside of a small customer base will have access to poke at it. Put simply, the criminal element has hitherto had almost 0 chance of getting a chance to go to town on it.

  20. example use by hey · · Score: 5, Funny

    ssh my-b1b
    login: root
    password: hellosss
    last login Tue Nov 18 17:22:14 EST 2008 from nsa
    # drop -4 bombs
    # exit

  21. There is a point to this by dltaylor · · Score: 2, Interesting

    besides /vertising for Green Hills:

    Modern warplanes are connected in a battlefield 'net that allows data, command and control to be passed between the planes (and satellite and ground). This is (obviously) a wireless network. Having a network stack and other interfaces hardened against intrusion makes it less likely that a battlefield adversary could either generate false data (the "magic" display in an F-22 paints the local AWACS as a "bandit", for example, and the pilot launches a missile), snoop data (the "stealthy" F-22s are here, here, here and here, so launch missiles at them), or perform some sort of DOS, degrading the systems capabilities. There are "well-funded and sophisticated attackers" who are likely to have those goals.

    If there was a business case, and so many of the developers didn't have, uh, reservations, about using their code in military equipment, the OpenBSD and, maybe, Linux kernel and glibc could be certified (stripped of a few components, probably, and with a few tweaks). With a "trusted" kernel, libraries, and tool chain, you build the rest of system from scratch, anyway. It's not like you're supposed to be browsing the public internet with IE or FF on a B-1's navigation system.

    There's no way for M$-Windows to be certified at EAL6+, because its design philosophy (the back doors are built in, not added on) is completely against any sort of security, and I don't think Vista is even EAL4+.

  22. Ubuntu! by jd · · Score: 2, Insightful

    It is headed by the only Linux nerd who could afford to chase a rating of 6 or above. (7 is the highest the EAL will go.) Another thing to consider is that EAL ratings are only valid for a combination of OS and hardware. So, running Windows on any box (even if functionally identical) to the configuration tested on makes the tests invalid. The true is arguably the same for Linux, except that you can download LTP and gain some measure of assurance (even if not blessed on that platform) that you've not broken any of the security.

    The highest old-style NSA rating (A1) is superior to the current EAL6+, and general-purpose OS' did achieve it. Genesis was one (and, no, not the one with the Phil Collins plugin module). EAL6+ looks to me to be about the same as the Orange Book B3 classification, which Trusted Irix achieved. Linux, if LTP was extended enough, could be provisionally ratified up to this level. If it ever was, then I could see vendors like IBM (who got Red Hat certified up to EAL4+) or private millionaires either individually or (more likely) jointly funding the certification.

    Of course, EAL-style security isn't everything you need. Security labels on packets would be good - isn't there some work on this already? Support for hardware MAC (mandatory access controls) for memory would be good, as that protects not only against memory access violations in software, but also against such violations with RDMA. (Of course, if the hardware isn't present, you don't get that security, but likewise if the OS support isn't present, you don't get the security.) Better support for hardware encryption - especially within OpenSSL and IPSec - would improve matters too. Coverity is a decent-enough static checker, but their much-vaunted cooperation with Open Source doesn't seem to be producing much in the way of results - I can't remember the last time anyone covered on Slashdot or LWN any work by them. Are the major Linux vendors considering alternatives like Klockwork or any of the theorum provers listed just the other day?

    Linux is already very good, but it hasn't received the severe auditing of OpenBSD (although, arguably, Linux does better when it comes to bugs that aren't security holes and also does better on the feature set and hardware supported). Perhaps a round or eleventy of severe auditing would be good for it. There again, perhaps there are other means of being close enough to that level of effectiveness without cutting back on the flexibility and without demanding unreasonable resources.

    --
    It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
    1. Re:Ubuntu! by bzipitidoo · · Score: 3, Informative

      Reading the comments in here, I think most of the posters don't understand what EAL 5+ is all about. Neither Linux nor Windows will ever achieve more than EAL 4. No, SELinux won't cut it. Neither will OpenBSD. 5+ requires formal verification. Do you understand what that means? You aren't testing everything you can think of, knowing that there will always be more problems because you can't think of everything and even if you could, you can't test everything. Instead, you have restricted the operations to such a small set that it actually is possible to prove every single possible permutation of all the operations will traverse and end only in known, secure states. For formal verification to be possible requires a small enough kernel, and Windows, Linux, and the BSDs are all far too large. They will never make EAL 5+. Hence the interest in microkernels.

      Now, there are some idiots who think they can get a system rubberstamped if only they bribe, pressure, wear down, or befuddle enough labs. (They're also idiots for thinking that the labs can be befuddled.) I should know, I was once stuck having to work with such. Considering the depths of chicanery to which those former acquaintances were willing to go, I am not 100% confident that a system that is given a high EAL rating actually deserves the rating.

      Green Hills has been hammering away at this for years, and now they've finally gotten their rating. It would greatly help with users' trust of the system if their code was open source. And it'd also help if there weren't more idiots trotting out the tired, old, and very wrong "security through obscurity" line that opening the source would compromise security. That sort of claim can only detract from any confidence that their product really is deserving of EAL 6, and that the people responsible for the evaluation know what they're doing.

      Another big problem, and maybe why they didn't make EAL 7, is the hardware. I have heard that in the past systems have been considered all of a piece-- can't put the software on any old hardware, has to be only on the exact hardware it was evaluated for. But it takes so many years to get there that the hardware becomes obsolete and useless long before they're done. That's one of the things that happened with GEMSOS (could you mean GEMSOS, not Genesis?)-- it's only certified on a 286 or some such.

      --
      Intellectual Property is a monopolistic, selfish, and defective concept. It is "tyranny over the mind of man"
  23. hehehe; this is a marketing joke by WindBourne · · Score: 3, Informative

    Lynx OS is EAL 7, and has been for a while. It will be quite some time before Greenhill makes it to EAL7. In the mean time, Lynuxworks uses Linux API, so that you have your choice of a real linux solution, or if needed, you can switch up to LynuxOS.

    --
    I prefer the "u" in honour as it seems to be missing these days.
  24. EAL = ToE(DUT) + ST(environment) by conspirator57 · · Score: 4, Interesting

    The EAL is only half of the equation. The Target of Evaluation (device under test) is subjected to EAL appropriate documentation and verification against a design document called the Security Target. This ST specifies the threat environment. For example the windows ST specifies that all authorized system users are benign and thus not a threat.

    --
    "If still these truths be held to be
    Self evident."
    -Edna St. Vincent Millay
  25. Re:Frosty Piss by Hucko · · Score: 2, Funny
    --
    Semi-automatic amateur armchair Australian philosopher; conjecture ready at any moment...