Research
.
Skip Search Box

SELinux Mailing List

Re: security enhancements outside of flask model

From: Stephen Smalley <sds_at_tislabs.com>
Date: Tue, 17 Apr 2001 13:28:25 -0400 (EDT)

With regard to kernel modules, SELinux controls the use of the Linux capabilities, so the ability to use the module-related system calls can be controlled by the policy. The example policy configuration protects the integrity of the module utilities, module configuration and module object files, and it restricts the ability to use the module calls.

The document available at http://www.nsa.gov/selinux/slinux-abs.html describes the current set of controls provided by SELinux. It also describes potential areas for adding further controls in the System Call Review section.

--
Stephen D. Smalley, NAI Labs
ssmalley@nai.com

On Tue, 17 Apr 2001, Michael N. Bernstein wrote:


> Is there any work being done in the selinux realm to secure other
> parts of the kernel? (e.g. kernel module, etc.).
-- You have received this message because you are subscribed to the selinux list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.
Received on Tue 17 Apr 2001 - 13:42:45 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service