2003
On the security of SELinux with a simplified policy
Proceedings of the IASTED International Conference on Communication, Network, and Information Security
- ,
- ,
- First page
- 79
- Last page
- 84
- Language
- Publishing type
- Research paper (international conference proceedings)
Security-Enhanced Linux (SELinux) is a secure operating system. SELinux implements some features in order to perform strong access control. However, the configuration of SELinux access control becomes very complex. Such complexity may cause misconfiguration which can harm the strong access control. SELinux Policy Editor is a configuration tool for SELinux. It is developed in order to reduce the complexity and the risk of misconfiguration. As a part of its support of configuration, this tool simplifies the configuration of SELinux by integrating configuration items for complicated access control policy of SELinux. Although we can originally define and use macros which integrate permissions in SELinux access control policy, the integrated permissions of SELinux Policy Editor and the macros differ fundamentally in whether the use of them is mandatory or discretionary. In this paper, we examine effects of the simplification by SELinux Policy Editor on an example access control policy and evaluate the security of the access control based on the simplified policy about Apache, a web server software.
- Link information
- ID information
-
- ISBN : 0889864020
- J-Global ID : 201902216287663384
- SCOPUS ID : 2642557127