The UNIX and Linux Forums  


Go Back   The UNIX and Linux Forums > Special Forums > Security > IT Security RSS
.
google unix.com



More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
script to monitor process running on server and posting a mail if any process is dead pradeepmacha Shell Programming and Scripting 13 03-06-2009 07:33 AM
Syntax coloring for .pc files in VIM editor RuchK UNIX for Dummies Questions & Answers 2 02-25-2008 07:22 AM
Killing of a process and send a mail if the process doesnot come up within 2 minutes Prince89 Shell Programming and Scripting 1 02-15-2008 07:10 PM
Coloring personal text in vim skkrish2 UNIX for Dummies Questions & Answers 1 02-01-2008 01:44 AM
how to start a process and make it sleep for 5 mins and then kill that process shrao Shell Programming and Scripting 6 03-27-2007 01:54 PM

 
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Bulgarian Greek Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old 11-06-2008
iBot's Avatar
iBot iBot is offline
Forum Robot Girl
  
 

Join Date: Sep 2000
Posts: 22,263
Process Coloring

There is a game called de Blob that has a pretty simple concept: move a blob around a city, run into a puddle of paint, and you turn into that color (or have that color mixed in with your current color.) Then when you run into a building, that building assumes the same color. So you're spreading different colors throughout a city, resulting in buildings and blocks hued red, orange, blue, green, etc. Simple but addictive, at least this is how the free version goes.

I thought about this game after attending a presentation at my local OWASP chapter that discussed the Process Coloring (PDF) project. It's similar to Perl Taint Mode. This project describes assigning a "color" (really a unique identifier) to processes at the syscall level. But I wondered if this could be used at a more abstract web application (e.g. .NET, J2EE, etc.) level when describing the rules of how objects interact.

From this presentation I took away two main advantages to Process Coloring.

  • Intrusion Prevention: you assign each process (or object) a color, and define the rules for each color (e.g. red cannot interface with yellow, green can only interface with green, blue and yellow, etc.)
  • Analysis: for log analysis, processes and events can be easily (and visually) grouped by color to quickly see the scope of the impact among other things.
What is most intriguing to me is being able to use both sides of the brain when it comes to web application security. Visually displaying volumes of data in an easily accessible and searchable way (e.g. the CNN Magic Wall used for election results) is the trend. Along these lines is SecViz; on this topic, a review of the book Applied Security Visualization was posted yesterday at Slashdot. Injecting some creativity into IT security encourages "out of the box" thinking, a valuable asset for discerning items of interest when establishing security, or during an investigation.





More...
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 03:39 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0