SELinux Security Policy Configuration System with Higher Level Language
- 論文の詳細を見る
Creating security policy for SELinux is difficult because access rules often exceed 10,000 and elements in rules such as permissions and types are understandable only for SELinux experts. The most popular way to facilitate creating security policy is refpolicy which is composed of macros and sample configurations. However, describing and verifying refpolicy based configurations is difficult because complexities of configuration elements still exist, using macros requires expertise and there are more than 100,000 configuration lines. The memory footprint of refpolicy which is around 5MB by default, is also a problem for resource constrained devices. We propose a system called SEEdit which facilitates creating security policy by a higher level language called SPDL and SPDL tools. SPDL reduces the number of permissions by integrated permissions and removes type configurations. SPDL tools generate security policy configurations from access logs and tool users knowledge about applications. Experimental results on an embedded system and a PC system show that practical security policies are created by SEEdit, i.e., describing configurations is semi-automated, created security policies are composed of less than 500 lines of configurations, 100 configuration elements, and the memory footprint in the embedded system is less than 500KB.
論文 | ランダム
- Effects of clothing type on physical performance after warming up under 15℃ condition
- 青色発光CaMgSi_2O6:Eu^蛍光体を用いた試作PDPパネルの発光特性
- 9107 台湾における歴史的建造物の保存政策に関する研究 : 新竹「空軍11村」及び「辛公館」を通してみた文化財登録制度の問題(韓国・朝鮮・台湾,建築歴史・意匠)
- 科学衛星搭載電源系の実績とLUNAR-A,PLANET-B電源系の開発状況
- 432 33ぶどう品種から分離した種子および果皮ポリフェノールの組成