节点文献
SELinux的安全机制和安全模型
Security mechanism and security model of SELinux
【摘要】 SELinux是美国安全局发布的一个集成在Linux内核中的新型强制访问控制(MAC)机制。为了提供细粒度的访问控制,SELinux采用RBAC模型和TE模型为主体和客体之间的交互设计了大量的安全策略,有效解决了自主访问控制(DAC)的脆弱性和传统MAC的不灵活性等问题。详细研究了SELinux的体系结构、安全模型和安全上下文,并以Apache服务器为例,介绍了如何定制SELinux以实现安全增强。
【Abstract】 Security-enhanced Linux(SELinux) is a modern Mandatory Access Control(MAC) mechanism in the Linux kernel,which was spearheaded by the Nation Security Agency(NSA) of America.To support fine-grained access control,SELinux implements a combination of Type Enforcement(TE) and Role-based Access Control(RBAC) to design a lot of security policies for the interactions between subjects and objects.It effectively resolves the weakness of the Discretionary Access Control(DAC) and the inflexibleness of the traditional MAC.The architecture,security models and security context of SELinux was studied in detail,and as an example,how to customize the Apache HTTP SELinux policy to enhance system security was also demonstrated.
【Key words】 security-enhanced Linux; RBAC model; TE model; security context;
- 【文献出处】 计算机应用 ,Journal of Computer Applications , 编辑部邮箱 ,2009年S1期
- 【分类号】TP393.08
- 【被引频次】28
- 【下载频次】620