Evaluation of Linux Security Frameworks
The number of threats to computers attached to networks continually increases. The focus of preventing security exploits has been on the network, while local exploits has been mostly overlooked. Many security problems in Unix systems stem from the way security is managed; by delegating all securit...
Main Author: | |
---|---|
Format: | Others |
Language: | English |
Published: |
Umeå universitet, Institutionen för datavetenskap
2010
|
Subjects: | |
Online Access: | http://urn.kb.se/resolve?urn=urn:nbn:se:umu:diva-36664 |
id |
ndltd-UPSALLA1-oai-DiVA.org-umu-36664 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-UPSALLA1-oai-DiVA.org-umu-366642018-01-13T05:15:33ZEvaluation of Linux Security FrameworksengKarlsson, ErikUmeå universitet, Institutionen för datavetenskap2010Computer SciencesDatavetenskap (datalogi) The number of threats to computers attached to networks continually increases. The focus of preventing security exploits has been on the network, while local exploits has been mostly overlooked. Many security problems in Unix systems stem from the way security is managed; by delegating all security decisions to object owners. There are a number of security frameworks which aim to remedy this in Linux by restricting access to kernel objects, such as files. Ericsson is interested in finding the best possible security frameworks for use with their Linux products.In this thesis, the available security frameworks are evaluated based on criteria given by Ericson. First, the theoretical foundation of computer security is explored to serve for an overview of the security frameworks and their properties. Then specific attributes are refined and their values gathered from each framework. These attributes then serve as a basis for selecting two frameworks for further testing.The selected frameworks are SELinux and AppArmor, based on commerical support, ease of integration, and overall protection measures. Tables with the collected attributes are presented for comparison.The frameworks TOMOYO and SMACK should have been given more consideration. AppArmor is not useful for the server-centric environment used at Ericsson. Student thesisinfo:eu-repo/semantics/masterThesistexthttp://urn.kb.se/resolve?urn=urn:nbn:se:umu:diva-36664UMNAD ; 849application/pdfinfo:eu-repo/semantics/openAccess |
collection |
NDLTD |
language |
English |
format |
Others
|
sources |
NDLTD |
topic |
Computer Sciences Datavetenskap (datalogi) |
spellingShingle |
Computer Sciences Datavetenskap (datalogi) Karlsson, Erik Evaluation of Linux Security Frameworks |
description |
The number of threats to computers attached to networks continually increases. The focus of preventing security exploits has been on the network, while local exploits has been mostly overlooked. Many security problems in Unix systems stem from the way security is managed; by delegating all security decisions to object owners. There are a number of security frameworks which aim to remedy this in Linux by restricting access to kernel objects, such as files. Ericsson is interested in finding the best possible security frameworks for use with their Linux products.In this thesis, the available security frameworks are evaluated based on criteria given by Ericson. First, the theoretical foundation of computer security is explored to serve for an overview of the security frameworks and their properties. Then specific attributes are refined and their values gathered from each framework. These attributes then serve as a basis for selecting two frameworks for further testing.The selected frameworks are SELinux and AppArmor, based on commerical support, ease of integration, and overall protection measures. Tables with the collected attributes are presented for comparison.The frameworks TOMOYO and SMACK should have been given more consideration. AppArmor is not useful for the server-centric environment used at Ericsson. |
author |
Karlsson, Erik |
author_facet |
Karlsson, Erik |
author_sort |
Karlsson, Erik |
title |
Evaluation of Linux Security Frameworks |
title_short |
Evaluation of Linux Security Frameworks |
title_full |
Evaluation of Linux Security Frameworks |
title_fullStr |
Evaluation of Linux Security Frameworks |
title_full_unstemmed |
Evaluation of Linux Security Frameworks |
title_sort |
evaluation of linux security frameworks |
publisher |
Umeå universitet, Institutionen för datavetenskap |
publishDate |
2010 |
url |
http://urn.kb.se/resolve?urn=urn:nbn:se:umu:diva-36664 |
work_keys_str_mv |
AT karlssonerik evaluationoflinuxsecurityframeworks |
_version_ |
1718608605927702528 |