首页> 外文会议>WSEAS International Conferences >Security architecture for a systematic administration of SELinux policies in distributed environments
【24h】

Security architecture for a systematic administration of SELinux policies in distributed environments

机译:安全架构,用于系统管理Selinux策略在分布式环境中

获取原文

摘要

Users and organizations seek to obtain from an operating system integrity, confidentiality, and availability in both hardware and software resources. These characteristics must come coupled with easy handling and administration. An operating system designed under the criteria of the class A1, consists of a collection of security strengthening mechanisms for the kernel. SELinux is an example of this type of operating system that supports several types of security policies applied to access control. In this article we address the problem of inconsistency in SELinux policies, which is present in distributed environments. To solve this problem, we propose an architecture that integrates a policy server for enabling a simple and secure administration. The policy server collects, integrates, and updates all policies that are applied in the distributed environment. We aim to achieve authenticity, integrity and confidentiality in the policy update process through the Kerberos V protocol. We propose a redundant policy server. We do not assure that the proposed architecture is bug free; it is impossible to guarantee a completely secure system. Nonetheless, we consider it a viable solution for centralized management of SELinux policies
机译:用户和组织寻求从硬件和软件资源中的操作系统完整性,机密性和可用性获取。这些特性必须加上易于处理和管理。在A1类标准下设计的操作系统包括一系列安全加强机制的内核。 Selinux是这种类型的操作系统的示例,它支持应用于访问控制的几种类型的安全策略。在本文中,我们解决了Selinux策略中不一致的问题,该策略存在于分布式环境中。为了解决这个问题,我们提出了一种集成策略服务器的架构,以实现简单安全的管理。策略服务器收集,集成和更新分布式环境中应用的所有策略。我们的目标是通过Kerberos V协议实现策略更新过程中的真实性,完整性和机密性。我们提出了一个冗余策略服务器。我们不保证拟议的架构是免费的;不可能保证完全安全的系统。尽管如此,我们认为这是一个可行的Selinux政策管理的可行解决方案

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号