Everything Computer Security Book: The Art of Deception : Controlling the Human Element of Security
The Art of Deception : Controlling the Human Element of Security

Everything Computer Security Book: Exploiting Software : How to Break Code
Exploiting Software : How to Break Code

Everything Computer Security Book: Computer Security: Art and Science
Computer Security: Art and Science

Everything Computer Security Book: Hacking Exposed (TM) Web Applications
Hacking Exposed (TM) Web Applications

Everything Computer Security Book: Inside Network Perimeter Security: The Definitive Guide to Firewalls, Virtual Private Networks (VPNs), Routers, and Intrusion Detection Systems
Inside Network Perimeter Security: The Definitive Guide to Firewalls, Virtual Private Networks (VPNs), Routers, and Intrusion Detection Systems

Everything Computer Security Book: Java Security (2nd Edition)
Java Security (2nd Edition)

Everything Computer Security Book: Cryptography and Network Security: Principles and Practice (3rd Edition)
Cryptography and Network Security: Principles and Practice (3rd Edition)

Everything Computer Security Book: Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management
Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management

Everything Computer Security Book: Steal This Computer Book 3: What They Won't Tell You About the Internet
Steal This Computer Book 3: What They Won't Tell You About the Internet

◄◄ Jump  More→ 1|2|3|4|Computer Security Links|More Guides Everything Computer Security Computer Security Directory
Learn More About This Directory
This directory sponsored by SIQL, a Spider Makers company...
Guides: Computer Security - Articles - Security-Enhanced Linux - Wikipedia

Security-Enhanced Linux

(Redirected from SELinux)

Security-Enhanced Linux (SELinux) is a Security-Enhanced version of GNU/Linux, which was primarily developed by the US National Security Agency (NSA) and released to the open source development community.

From NSA Security-enhanced Linux Team:

"NSA Security-enhanced Linux is a set of patches to the Linux kernel and some utilities to incorporate a strong, flexible mandatory access control (MAC) architecture into the major subsystems of the kernel. It provides a mechanism to enforce the separation of information based on confidentiality and integrity requirements, which allows threats of tampering and bypassing of application security mechanisms to be addressed and enables the confinement of damage that can be caused by malicious or flawed applications. It includes a set of sample security policy configuration files designed to meet common, general-purpose security goals."

Security-enhanced Linux is a research prototype of the Linux kernel and a number of utilities with enhanced security functionality designed simply to demonstrate the value of mandatory access controls to the Linux community and how such controls could be added to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of type enforcement, role-based access control, and multi-level security.

The security-enhanced Linux kernel enforces mandatory access control policies that confine user programs and system servers to the minimum amount of privilege they require to do their jobs. When confined in this way, the ability of these user programs and system daemons to cause harm when compromised (via buffer overflows or misconfigurations, for example) is reduced or eliminated. This confinement mechanism operates independently of the traditional Linux access control mechanisms. It has no concept of a "root" super-user, and does not share the well-known shortcomings of the traditional Linux security mechanisms (such as a dependence on setuid/setgid binaries).

The security of an unmodified Linux system depends on the correctness of the kernel, all the privileged applications, and each of their configurations. A problem in any one of these areas may allow the compromise of the entire system. In contrast, the security of a modified system based on the security-enhanced Linux kernel depends primarily on the correctness of the kernel and its security policy configuration. While problems with the correctness or configuration of applications may allow the limited compromise of individual user programs and system daemons, they do not pose a threat to the security of other user programs and system daemons or to the security of the system as a whole. SELinux merged with the 2.6 series Linux Kernel.

Features

See also

External links

Everything Computer Security Book: The Art of Deception : Controlling the Human Element of Security
The Art of Deception : Controlling the Human Element of Security
  Everything Computer Security Book: Exploiting Software : How to Break Code
Exploiting Software : How to Break Code
  Everything Computer Security Book: Computer Security: Art and Science
Computer Security: Art and Science
  Everything Computer Security Book: Hacking Exposed (TM) Web Applications
Hacking Exposed (TM) Web Applications
 
Everything Computer Security Book: Inside Network Perimeter Security: The Definitive Guide to Firewalls, Virtual Private Networks (VPNs), Routers, and Intrusion Detection Systems
Inside Network Perimeter Security: The Definitive Guide to Firewalls, Virtual Private Networks (VPNs), Routers, and Intrusion Detection Systems
  Everything Computer Security Book: Java Security (2nd Edition)
Java Security (2nd Edition)
  Everything Computer Security Book: Cryptography and Network Security: Principles and Practice (3rd Edition)
Cryptography and Network Security: Principles and Practice (3rd Edition)
  Everything Computer Security Book: Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management
Information Security Policies, Procedures, and Standards: Guidelines for Effective Information Security Management
 
Everything Computer Security Book: Steal This Computer Book 3: What They Won't Tell You About the Internet
Steal This Computer Book 3: What They Won't Tell You About the Internet
   
From http://en.wikipedia.org/wiki/SELinux
◄◄ Jump  More→ 1|2|3|4|Computer Security Links|More Guides Everything Computer Security Computer Security Directory

Valid CSS! Valid HTML 4.01!
This custom Guide To The Internet produced by Siql. Visit us today, and find out how to get your own custom guide to the Internet, and how to get your site listed in our guides.
Copyright 1995-2004 by Siql. All Rights Reserved.