■ National Information Assurance Research Laboratory ■
1
SELinux Year in Review Stephen D. Smalley sds@tycho.nsa.gov - - PowerPoint PPT Presentation
SELinux Year in Review Stephen D. Smalley sds@tycho.nsa.gov National Information Assurance Research Laboratory National Security Agency 1 National Information Assurance Research Laboratory Outline SELinux Background The Year
■ National Information Assurance Research Laboratory ■
1
■ National Information Assurance Research Laboratory ■
2
■ National Information Assurance Research Laboratory ■
3
– No protection against flawed or malicious applications. – Key missing feature: Mandatory Access Control (MAC)
– were not mainstream – used a fixed, limited MAC model (BLP/ Biba)
■ National Information Assurance Research Laboratory ■
4
■ National Information Assurance Research Laboratory ■
5
– Type Enforcement (TE) – Role- Based Access Control (RBAC) – Optionally Multi- Level Security (MLS)
■ National Information Assurance Research Laboratory ■
6
■ National Information Assurance Research Laboratory ■
7
– Contain damage from 0- day exploits. – Reduce need for immediate security patching of applications.
■ National Information Assurance Research Laboratory ■
8
– With several daemons locked down including Apache...
– With strict policy, servers only.
– Separate packages available for Debian unstable, SuSE.
■ National Information Assurance Research Laboratory ■
9
– Targeted policy has grown to ~120 confined domains.
– Patches upstreamed into Debian unstable. – Separate back- port packages available for Debian stable.
■ National Information Assurance Research Laboratory ■
10
■ National Information Assurance Research Laboratory ■
11
■ National Information Assurance Research Laboratory ■
12
– Source modules only, little encapsulation.
– Difficult to customize and still track vendor policy updates.
– Manipulation of text files, execution of policy build process.
■ National Information Assurance Research Laboratory ■
13
– Build and package policy modules separately.
– Explicit interfaces, strong encapsulation.
– Supports module operations and variety of local policy customizations.
– Polgen, SEEdit, SLIDE, CDS Framework.
■ National Information Assurance Research Laboratory ■
14
■ National Information Assurance Research Laboratory ■
15
■ National Information Assurance Research Laboratory ■
16
■ National Information Assurance Research Laboratory ■
17
■ National Information Assurance Research Laboratory ■
18
■ National Information Assurance Research Laboratory ■
19