Linux Security Modules: General security support for the Linux kernel

被引:0
|
作者
Wright, C
Cowan, C
Smalley, S
Morris, J
Kroah-Hartman, G
机构
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The access control mechanisms of existing mainstream operating systems are inadequate to provide strong system security. Enhanced access control mechanisms have failed to win acceptance into mainstream operating systems due in part to a lack of consensus within the security community on the right solution. Since general-purpose operating systems must satisfy a wide range of user requirements, any access control mechanism integrated into such a system must be capable of supporting many different access control models. The Linux Security Modules (LSM) project has developed a lightweight, general purpose, access control framework for the mainstream Linux kernel that enables many different access control models to be implemented as loadable kernel modules. A number of existing enhanced access control implementations, including Linux capabilities, Security-Enhanced Linux (SELinux), and Domain and Type Enforcement (DTE), have already been adapted to use the LSM framework. This paper presents the design and implementation of LSM and discusses the challenges in providing a truly general solution that minimally impacts the Linux kernel.
引用
收藏
页码:17 / 31
页数:15
相关论文
共 50 条
  • [1] Trusted path execution for the Linux 2.6 kernel as a Linux Security Module
    Rahimi, NA
    USENIX ASSOCIATION PROCEEDINGS OF THE FREENIX TRACK 2004 USENIX ANNUAL TECHNICAL CONFERENCE, 2004, : 73 - 80
  • [2] LBM: A Security Framework for Peripherals within the Linux Kernel
    Tian, Dave
    Hernandez, Grant
    Choi, Joseph I.
    Frost, Vanessa
    Johnson, Peter C.
    Butler, Kevin R. B.
    2019 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2019), 2019, : 967 - 984
  • [3] Design and implementation of secure Linux kernel security functions
    Shi, W.C.
    Sun, Y.F.
    Liang, H.L.
    Zhang, X.F.
    Zhao, Q.S.
    Shan, Z.Y.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2001, 38 (10):
  • [4] Analysis and Study of Security Mechanisms inside Linux Kernel
    Zhai, Gaoshou
    Li, Yaodong
    SECTECH: 2008 INTERNATIONAL CONFERENCE ON SECURITY TECHNOLOGY, PROCEEDINGS, 2008, : 58 - 61
  • [5] Analyzing the Overhead of File Protection by Linux Security Modules
    Zhang, Wenhui
    Liu, Peng
    Jaeger, Trent
    ASIA CCS'21: PROCEEDINGS OF THE 2021 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 393 - 406
  • [6] Hotswapping Linux kernel modules
    Lee, YF
    Chang, RC
    JOURNAL OF SYSTEMS AND SOFTWARE, 2006, 79 (02) : 163 - 175
  • [7] Travelling with Linux malware Is Linux security for real?
    Rautiainen, Sami
    Information Security Technical Report, 2001, 6 (04): : 58 - 64
  • [8] Linux Security: A Survey
    Yaswinski, Matthew R.
    Chowdhury, Md Minhaz
    Jochen, Mike
    2019 IEEE INTERNATIONAL CONFERENCE ON ELECTRO INFORMATION TECHNOLOGY (EIT), 2019, : 357 - 362
  • [9] Reflections on the virtues of modularity: a case study in linux security modules
    Blaich, Andrew
    Thain, Douglas
    Striegel, Aaron
    SOFTWARE-PRACTICE & EXPERIENCE, 2009, 39 (15): : 1235 - 1251
  • [10] Translating Security Policy to Executable code for Sandboxing Linux Kernel
    Mohanty, Hrushikesha
    VenkataSwamy, M.
    Ramaswamy, Srini
    Shyamasundar, R. K.
    2009 THIRD UKSIM EUROPEAN SYMPOSIUM ON COMPUTER MODELING AND SIMULATION (EMS 2009), 2009, : 124 - +