Extensible Security For X - Motivation and Design 2004.pdf

(598 KB) Pobierz
Extensible Security For X:
Motivation and Design
Eamon Walsh
SELinux Team
Information Assurance Research
National Security Agency
Summary
Working towards an open source, trusted 
desktop.
Need to have infrastructure for doing fine­
grained access control in the X server.
Hooks only – no specific policies.
Local to server – no protocol changes.
Branch development model.
What Is SELinux?
Fine­grained Mandatory Access Control for 
Linux.
Policy system based on Flask architecture.
Strong separation of security domains and roles.
Controls over process execution & resource access.
Diminish severity of program vulnerabilities.
Kernel module; uses LSM security hooks.
Some userspace changes.
SELinux Timeline
1
985
LOCK (early Type Enforcement)
1990
1995
1999
2000
2001
2002
2003
Present
DTMach / DTOS
Utah Fluke / Flask
2.2 Linux Kernel (patch)
2.4 Linux Kernel (patch)
LSM
2.6 Linux Kernel (mainline)
Zgłoś jeśli naruszono regulamin