首页> 外文会议>IEEE Symposium on Visualization for Cyber Security >V3SPA: A visual analysis, exploration, and diffing tool for SELinux and SEAndroid security policies
【24h】

V3SPA: A visual analysis, exploration, and diffing tool for SELinux and SEAndroid security policies

机译:V3SPA:针对SELinux和SEAndroid安全策略的可视化分析,探索和区分工具

获取原文

摘要

SELinux policies have enormous potential to enforce granular security requirements, but the size and complexity of SELinux security policies make them challenging for security policy administrators to determine whether the implemented policy meets an organization's security requirements. To address the challenges in developing and maintaining SELinux security policies, this paper presents V3SPA (Verification, Validation and Visualization of Security Policy Abstractions). V3SPA is a tool that can import SELinux and Security Enhancements (SE) for Android source or binary policies and visualize them using two views: A policy explorer, and a policy differ. The policy explorer supports users in exploring a policy and understanding the relationships defined by the policy. The diffing view is designed to support differential policy analysis, showing the changes between two versions of a policy. The main contributions of this paper are 1) the design of the policy explorer, and the design and novel usecase for the policy differ, 2) a report on system design considerations to enable the graph visualizations to scale up to visualizing policies with tens of thousands of nodes and edges, and 3) a survey of five SELinux and SE for Android policy developers and analysts. The results of the survey indicate a need for tools such as V3SPA to help policy workers understand the big picture of large, complex security policies.
机译:SELinux策略具有执行精细安全要求的巨大潜力,但是SELinux安全策略的规模和复杂性使它们对安全策略管理员确定所实施的策略是否满足组织的安全要求提出了挑战。为了解决在开发和维护SELinux安全策略方面的挑战,本文介绍了V3SPA(安全策略抽象的验证,验证和可视化)。 V3SPA是一种工具,可以为Android源或二进制策略导入SELinux和安全增强(SE)并使用两个视图将其可视化:策略浏览器和策略不同。策略浏览器支持用户浏览策略并了解该策略定义的关系。差异视图旨在支持差异策略分析,以显示策略的两个版本之间的更改。本文的主要贡献是:1)策略浏览器的设计,策略的设计和新颖用例有所不同; 2)关于系统设计考虑因素的报告,以使图形可视化能够扩展到可视化策略,并具有成千上万的策略3)针对Android策略开发者和分析师的五个SELinux和SE的调查。调查结果表明需要使用V3SPA之类的工具来帮助策略制定者了解大型,复杂的安全策略的概况。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号