Evaluation of Linux Security Frameworks

  The number of threats to computers attached to networks continually increases. The focus of preventing security exploits has been on the network, while local exploits has been mostly overlooked. Many security problems in Unix systems stem from the way security is managed; by delegating all securit...

Full description

Bibliographic Details
Main Author: Karlsson, Erik
Format: Others
Language:English
Published: Umeå universitet, Institutionen för datavetenskap 2010
Subjects:
Online Access:http://urn.kb.se/resolve?urn=urn:nbn:se:umu:diva-36664
id ndltd-UPSALLA1-oai-DiVA.org-umu-36664
record_format oai_dc
spelling ndltd-UPSALLA1-oai-DiVA.org-umu-366642018-01-13T05:15:33ZEvaluation of Linux Security FrameworksengKarlsson, ErikUmeå universitet, Institutionen för datavetenskap2010Computer SciencesDatavetenskap (datalogi)  The number of threats to computers attached to networks continually increases. The focus of preventing security exploits has been on the network, while local exploits has been mostly overlooked. Many security problems in Unix systems stem from the way security is managed; by delegating all security decisions to object owners. There are a number of security frameworks which aim to remedy this in Linux by restricting access to kernel objects, such as files. Ericsson is interested in finding the best possible security frameworks for use with their Linux products.In this thesis, the available security frameworks are evaluated based on criteria given by Ericson. First, the theoretical foundation of computer security is explored to serve for an overview of the security frameworks and their properties. Then specific attributes are refined and their values gathered from each framework. These attributes then serve as a basis for selecting two frameworks for further testing.The selected frameworks are  SELinux  and AppArmor, based on commerical support, ease of integration, and overall protection measures. Tables with the collected attributes are presented for comparison.The frameworks  TOMOYO and SMACK  should have been given more consideration. AppArmor is not useful for the server-centric environment used at Ericsson. Student thesisinfo:eu-repo/semantics/masterThesistexthttp://urn.kb.se/resolve?urn=urn:nbn:se:umu:diva-36664UMNAD ; 849application/pdfinfo:eu-repo/semantics/openAccess
collection NDLTD
language English
format Others
sources NDLTD
topic Computer Sciences
Datavetenskap (datalogi)
spellingShingle Computer Sciences
Datavetenskap (datalogi)
Karlsson, Erik
Evaluation of Linux Security Frameworks
description   The number of threats to computers attached to networks continually increases. The focus of preventing security exploits has been on the network, while local exploits has been mostly overlooked. Many security problems in Unix systems stem from the way security is managed; by delegating all security decisions to object owners. There are a number of security frameworks which aim to remedy this in Linux by restricting access to kernel objects, such as files. Ericsson is interested in finding the best possible security frameworks for use with their Linux products.In this thesis, the available security frameworks are evaluated based on criteria given by Ericson. First, the theoretical foundation of computer security is explored to serve for an overview of the security frameworks and their properties. Then specific attributes are refined and their values gathered from each framework. These attributes then serve as a basis for selecting two frameworks for further testing.The selected frameworks are  SELinux  and AppArmor, based on commerical support, ease of integration, and overall protection measures. Tables with the collected attributes are presented for comparison.The frameworks  TOMOYO and SMACK  should have been given more consideration. AppArmor is not useful for the server-centric environment used at Ericsson.
author Karlsson, Erik
author_facet Karlsson, Erik
author_sort Karlsson, Erik
title Evaluation of Linux Security Frameworks
title_short Evaluation of Linux Security Frameworks
title_full Evaluation of Linux Security Frameworks
title_fullStr Evaluation of Linux Security Frameworks
title_full_unstemmed Evaluation of Linux Security Frameworks
title_sort evaluation of linux security frameworks
publisher Umeå universitet, Institutionen för datavetenskap
publishDate 2010
url http://urn.kb.se/resolve?urn=urn:nbn:se:umu:diva-36664
work_keys_str_mv AT karlssonerik evaluationoflinuxsecurityframeworks
_version_ 1718608605927702528