SELinux Security Policy Configuration System with Higher Level Language
スポンサーリンク
概要
- 論文の詳細を見る
Creating security policy for SELinux is difficult because access rules often exceed 10,000 and elements in rules such as permissions and types are understandable only for SELinux experts. The most popular way to facilitate creating security policy is refpolicy which is composed of macros and sample configurations. However, describing and verifying refpolicy based configurations is difficult because complexities of configuration elements still exist, using macros requires expertise and there are more than 100,000 configuration lines. The memory footprint of refpolicy which is around 5MB by default, is also a problem for resource constrained devices. We propose a system called SEEdit which facilitates creating security policy by a higher level language called SPDL and SPDL tools. SPDL reduces the number of permissions by integrated permissions and removes type configurations. SPDL tools generate security policy configurations from access logs and tool users knowledge about applications. Experimental results on an embedded system and a PC system show that practical security policies are created by SEEdit, i.e., describing configurations is semi-automated, created security policies are composed of less than 500 lines of configurations, 100 configuration elements, and the memory footprint in the embedded system is less than 500KB.
論文 | ランダム
- あなたの店舗立地はどのタイプ?「巣ごもり型」「迎客型」「移動型」に応じたシルバーウイーク「旬の売り方・演じ方」
- 「景気は悪くない」楽天市場の快進撃で、三木谷浩史社長の強気戦略 (特集 巣ごもり消費を背景に リアルを圧倒するeコマース)
- 非行のあった少年の保護者に対する支援(自主シンポジウム51,日本特殊教育学会第47回大会シンポジウム報告)
- いずれ日中対決の日はやってくる (巻頭ぶち抜き大特集 21世紀の怪物 中国とどう闘うか--このままでは日本は必ずやられる)
- 国立歴史民俗博物館蔵高松宮家伝来禁裏本の「系図」の史料群について