On mySimon: Cotton Pajamas: Style While Lounging
BNET Business Network:
BNET
TechRepublic
ZDNet

March 23rd, 2005

Is Windows more secure than Linux for web serving?

Posted by George Ou @ 2:49 am

Categories: Security

Tags:

At the risk of starting another holy war, I had to comment on this story. Robert Lemos reports?on a study?that concludes Windows is more secure than Linux for Web serving. Although the test was funded by Microsoft, the two authors of the study did publish all test methodology so that it can be independently scrutinized and repeated. In general, vendor-funded studies almost always favor the vendors that fund them. This statistic obviously makes sense, since no company would ever fund a study that they either expected to lose or if they couldn’t get the researchers to "fudge" the numbers in their favor. The big question here: Is this a case of fudging the numbers or is there some truth to it?

Since this was primarily a comparison of Web server technology, we’re mainly talking about IIS 6.0 and Apache 2.x. From a real world standpoint, it can be argued that other vulnerabilities pertaining to the underlying operating systems and other non-Web related components for Windows or Linux are less of a security priority.?A locked down Web server will only have TCP ports 80 and 443 open on the local firewall, whether you’re talking about Linux IPChains or Windows Firewall. Therefore, the only thing that is exposed beyond the Ethernet adapter of the server is IIS 6.0 or Apache 2.x, and these are the main things we need to worry about when evaluating Web servers. So let’s compare these two platforms’ security track records.

If we look at the SecurityFocus Web site vulnerability search page and we type in keywords "Apache 2" and "IIS 6.0", we will see that there is basically only one security advisory for IIS 6.0 since its inception, and we can see that there are many advisories for Apache 2. Unfortunately, the results don’t really elaborate on what this actually means in terms of severity of the advisories. A better?security research site is secunia.com which does go into much more detail with nice graphical analysis. When I searched Secunia, I found the following results.

IIS 6.0 track record:
IIS 6.0 has?only three advisories listed for for the last two years and none of the advisories were rated beyond moderate.?Two advisories were moderate and?one was rated low. Only one was not patched.

Apache 2.0.x track record:
Apache 2.0 has 22 security advisories and two were not patched. One was rated high,?seven were rated moderate, and 13 were rated low.

Both comparisons were from the year 2003 to 2005 and represent the most modern versions of their respective platforms, so it’s a pretty fair comparison. Based on this information, it is easy to conclude that IIS 6.0 has a much better track record than Apache 2.0.x and that Apache needed to be patched more frequently. In light of this data, we have to wonder if Windows 2003 server really is better than Linux and Apache for the purpose of Web serving. What do you think? Talkback and let your opinion be heard.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 38 Talkback(s)
Who reports exploits?
It is well known that epidemiological statistics on diseases are skewed by changing attitudes toward various "afflictions" -- many non-life-threatening ailments appear to be on the rise because they a... (Read the rest)
Posted by: Jick Posted on: 11/03/05 You are currently: a Guest | | Terms of Use
Is the J2EE with Sun Servers better than Linux and Windows  Roving_Reporter | 03/23/05
Doesn't Apache run on both Windows and Linux?  Zogg | 03/23/05
Newspeak?  seosamh_z | 03/23/05
Newspeak? Nah, just ignorance  LGLisle | 03/23/05
yet another round of pointless banter  barnesanova | 03/23/05
risk  dwest_z | 03/23/05
Comparisons  Roger Ramjet | 03/23/05
Completely agree  Bata Srki | 03/23/05
All stats were from 2003 - 2005  george_ou | 03/23/05
Its not a Matter of which one is "more secure"  jfp | 03/23/05
Agreed that it's not a matter of vulnerability counts...  droby10 | 03/23/05
Most cogent argument so far  mmarth | 03/23/05
Wow  IT Scion | 03/24/05
You think? We're talking about servers!  Zogg | 03/26/05
The day is going to come...  Qbt | 03/23/05
Is another company going to buy Windows from MS?  Xunil_Sierutuf | 03/23/05
Yes, it could happen  alterego_z | 03/23/05
It Could Happen?  Jkirk3279 | 03/23/05
No such thing  IT Scion | 03/24/05
Erroneous numbers  mmarth | 03/23/05
What about compromised numbers?  rpmyers1 | 03/23/05
Your best bet there is...  droby10 | 03/23/05
mi2g just makes stuff up -nt-  emcee_z | 03/23/05
Reading 101  droby10 | 03/23/05
Not about what I want to see  emcee_z | 03/23/05
Then feel fortunate in the fact...  droby10 | 03/23/05
The superficial analysis works for you  Richard Flude | 03/23/05
You're misinterpreting the results  george_ou | 03/23/05
I think what he's saying...  droby10 | 03/23/05
Show me where it affects a web server  george_ou | 03/24/05
Here you go  Richard Flude | 03/24/05
You're partially right  george_ou | 03/24/05
Why?  Richard Flude | 03/24/05
MS is taking security more seriously than Linux  coder_z | 03/24/05
Right...  Sabz5150 | 03/26/05
usual apples and oranges ...  mdfischer | 03/25/05
Ken Brown: Validated  Junior_z | 03/31/05
Who reports exploits?  Jick | 11/03/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement
    Click Here

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads