Information and network security solutions that claim to protect businesses from bad actors on the Internet is big business. Unfortunately, many of those vendors sell promises of mitigation based on fear. The best way to understand how you are actually being protected is to audit the security software being used. An independent code review is one of the most fundamental and significant steps that occurs during the software development process.
In 2016, Netgate engaged with Infosec Global, an independent, third-party firm with over 150 years of collective experience in the security and IT industry, to conduct a top to bottom, post-commit audit of pfSense software version 2.3.2. A post-commit audit is where the source code is reviewed after being committed to the codebase and may already be used in production environments. Any bugs that are identified or vulnerabilities found during the code review are patched and recommitted to the codebase.
Conducting an independent code review dramatically helps improve the quality of the product. Netgate is dedicated to responding effectively to new threat advisories and mitigating any associated concerns immediately through a transparent, rapid release process to our customers around the world. Previous examples of this include, but are not limited to: CVE-2014-6271 “Shellshock” and CVE-2014-0160 “Heartbleed” from 2014. Netgate engineers analyzed, patched, tested and deployed a new version in 48 hours while other major vendors took weeks to issue updates for their products.
For this project, Netgate provided Infosec Global with the Netgate XG-2758 1U Security Gateway Appliance with pfSense software version 2.3.2 installed with a default production configuration and the source code included the commercial features which are not included in the community edition as the target for this engagement. The software provided for the purpose of this audit is only available pre-installed on pfSense security appliances from Netgate.
This project was managed by Technical Director Ahmed Techini and Security Engineers Paul Lam and Daniele Bastianello. ISG employed both automated and manual code review approaches to conduct the source code review, as outlined in the final report. All evaluation activities were conducted in the ISG Globus Cyber Assurance facility based in Ottawa between early September to mid-October 2016 with an addendum based on previously-mitigated items issued in December 2016.
“The overall opinion of the engagement team is that the Netgate XG-2758-1U pfSense security appliance is a well designed, robust and secure security appliance with a large community behind it making this product an easy choice to recommend for businesses of any size.”
Infosec Global scores threats on a bottom-up percentage scale, with 0% being a perfect score and 100% being most critical. As indicated in the audit report, pfSense 2.3.2 scored an outstanding 1%, which included concerns that were mitigated during the audit process with the release of pfSense software version 2.3.2_p1, or that were raised but do not apply to the firmware reviewed.
Infosec Global develops innovative cybersecurity software and solutions for enterprise and government. Our Globus™ product line includes Crypto and Multi-Crypto, Network Protection and Cyber Assurance. Our team consists of renowned experts, the world’s best cryptographers, inventors of the foundations of Internet security, and global leaders at the leading edge of cyber security. We empower customers with security solutions they control for highly complex regulatory environments. With offices in Canada, Switzerland and the United States, we’re equipped to meet trust needs, compliance requirements and get results. To learn more, visit www.infosecglobal.com
Netgate is a leading networking and security company and the home of pfSense; the world’s most popular open-source Firewall/Router/VPN platform. Our expertise in networking and security, combined with Intel-powered networking technologies, enables us to deliver to businesses of all sizes next-generation networking appliances, platforms and intelligent security solutions from the edge to the cloud. Netgate is shaping the future of high-performance secure communication. Secure networks start here.™ Visit www.netgate.com for more information.