~ Office Supplies ~~ Buy Posters ~~ A-Z Products ~~ Website Advertising


Security-Enhanced Linux - Wikipedia

<<Up     Contents

Security-Enhanced Linux

Redirected from SE Linux

The NSA has released Security-Enhanced Linux a security-enhanced version of the Linux operating system kernel and operating system utilities which contains support for mandatory access controls[?] based on the principle of least privilege[?].

Security-enhanced Linux is a research prototype of the Linux kernel and a number of utilities with enhanced security functionality designed simply to demonstrate the value of mandatory access controls to the Linux community and how such controls could be added to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system[?]. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement[?], Role-based Access Control[?], and Multi-level Security[?].

The Security-enhanced Linux kernel enforces mandatory access control policies that confine user programs and system servers to the minimum amount of privilege they require to do their jobs. When confined in this way, the ability of these user programs and system daemons to cause harm when compromised (via buffer overflows or misconfigurations, for example) is reduced or eliminated. This confinement mechanism operates independently of the traditional Linux access control mechanisms. It has no concept of a "root" super-user, and does not share the well-known shortcomings of the traditional Linux security mechanisms (such as a dependence on setuid/setgid binaries).

The security of an unmodified Linux system depends on the correctness of the kernel, all the privileged applications, and each of their configurations. A problem in any one of these areas may allow the compromise of the entire system. In contrast, the security of a modified system based on the Security-enhanced Linux kernel depends primarily on the correctness of the kernel and its security policy configuration. While problems with the correctness or configuration of applications may allow the limited compromise of individual user programs and system daemons, they do not pose a threat to the security of other user programs and system daemons or to the security of the system as a whole.

Features of security-enhanced Linux:

See also:

External links:

wikipedia.org dumped 2003-03-17 with terodump




 
 
Orange Mexican Potch OPAL gem stone jewel Loose faceted cut jewelry gemstone 8x6 mm single 8x6mm ov
 Orange Mexican Potch OPAL jewel Loose ed cut jewelry 8x6 mm single 8x6mm ov 
 
100 ctw unknown RED GARNETS gem stones Faceting cabbing rough crystal Tiny melee accent up to 2 ct
 100 ctw unknown RED GARNETS ing cabbing crystal Tiny melee accent up to 2 ct 
 
SS .925 Sterling Silver 18" inch box chain 1 mm for gemstone jewelry pendant necklace spring clasp
 SS .925 Sterling Silver 18" inch box chain 1 mm for jewelry pendant necklace spring clasp 
 
28 carats cts Tigereye yellow gold TigerIron Jasper gem tumble polished Cabbing cab tiger iron rough
 28 carats cts Tigereye yellow gold TigerIron Jasper tumble polished Cabbing cab tiger iron  
 
Red green AMMOLITE gem stone Freeform cabochon cabbing jewelry rough Ammonite opal 10 carats 2 grams
 Red green AMMOLITE Freeform cabochon cabbing jewelry Ammonite opal 10 carats 2 grams