Dreaganos: And you have proof for that ? Or is that just the typical internet "i say it is a fact so it is a fact" crap ?
Name one Linux firewall that lets you control network traffic on a per-application/per-process basis AND lets you limit that access by port/destination, like Outpost/Kerio/Sygate/Jetico or even the basic Windows Firewall does.
Name one Linux application that lets you control what processes can launch, what drivers they can load, what system configuration changes they can make or whether or not they can access /dev/mem (equivalent to accessing physical memory in Windows and a way for malware to bypass security software entirely) - like Process Guard, System Safety Monitor or App/RegDefend on Windows.
I've spent nearly 20 years keeping an eye out for such utilities and drawn a blank, so I'd actually be delighted if you (or anyone else) can prove me wrong.
And just to prevent previous suggestions from being repeated - SELinux is out because it is non-interactive (you have to define policies in advance, making it impractical for everyday use) and it doesn't cover all the options above. TuxGuardian/Douane and similar utilities are out because they only provide a yes/no option for network access without allowing you to fine-tune it further.