首页> 外文会议>IASTED conference on communication, network, and information security >ON THE SECURITY OF SELINUX WITH A SIMPLIFIED POLICY
【24h】

ON THE SECURITY OF SELINUX WITH A SIMPLIFIED POLICY

机译:关于SELinux的安全性,简化政策

获取原文
获取外文期刊封面目录资料

摘要

Security-Enhanced Linux (SELinux) is a secure operating system. SELinux implements some features in order to perform strong access control. However, the configuration of SELinux access control becomes very complex. Such complexity may cause misconfiguration which can harm the strong access control. SELinux Policy Editor is a configuration tool for SELinux. It is developed in order to reduce the complexity and the risk of misconfiguration. As a part of its support of configuration, this tool simplifies the configuration of SELinux by integrating configuration items for complicated access control policy of SELinux. Although we can originally define and use macros which integrate permissions in SELinux access control policy, the integrated permissions of SELinux Policy Editor and the macros differ fundamentally in whether the use of them is mandatory or discretionary. In this paper, we examine effects of the simplification by SELinux Policy Editor on an example access control policy and evaluate the security of the access control based on the simplified policy about Apache, a web server software.
机译:安全增强的Linux(SELinux)是一个安全的操作系统。 Selinux实现了一些功能,以执行强大的访问控制。但是,SELinux访问控制的配置变得非常复杂。这种复杂性可能导致错误配置,这可能会损害强的访问控制。 Selinux Policy Editor是Selinux的配置工具。它是开发的,以降低复杂性和错误配置的风险。作为其配置的支持的一部分,该工具通过对Selinux的复杂访问控制策略集成配置项来简化SELinux的配置。虽然我们最初可以定义和使用宏,宏集成了SELinux访问控制策略中的权限,但SELinux策略编辑器的集成权限和宏在根本上不同地不同地不同地不同。在本文中,我们在示例访问控制策略上检查SELInux Policy Editor的简化效果,并根据关于A​​pache,Web服务器软件的简化策略评估访问控制的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号