login
Header Space

 
 

Re: TOMOYO Linux Security Goal

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Tetsuo Handa <penguin-kernel@...>
Cc: <linux-security-module@...>, <linux-kernel@...>
Date: Wednesday, December 26, 2007 - 12:42 pm

Quoting Tetsuo Handa (penguin-kernel@I-love.SAKURA.ne.jp):

Are they in fact unique?


This section seems to me to be the most important one, and could really
use a little more detail.


This email promised me a security goal, but instead of laying out
requirements it meets, its says it meets "practical requirements".
That's really not helpful.

What kernel resources does TOMOYO authorize?  All those which SELinux
does?


So your point was that your main goal is simplicity?

Ok a few things you could add:

	1. Tomoyo provide no sort of information flow control.

	2. TOMOYO is purely restrictive.

	3. Learning mode is primary source of policy so you
	   depend on change of behavior to detect intruders.
	
	4. but any intruder who attempts to do something which
	   the compomised sftware wouldn't have done should be
	   stopped and detected.

This gives a precise (though perhaps wrong as I'm guessing :) picture
of what TOMOYO can do and how it fits in with SMACK, apparmor,
capabilities, and SELinux.

thanks,
-serge

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
TOMOYO Linux Security Goal, Tetsuo Handa, (Tue Dec 25, 8:33 am)
Re: TOMOYO Linux Security Goal, Serge E. Hallyn, (Wed Dec 26, 12:42 pm)
Re: TOMOYO Linux Security Goal, Tetsuo Handa, (Thu Dec 27, 9:00 am)
Re: TOMOYO Linux Security Goal, Serge E. Hallyn, (Thu Dec 27, 10:54 am)
Re: TOMOYO Linux Security Goal, Tetsuo Handa, (Fri Dec 28, 10:32 am)
Re: TOMOYO Linux Security Goal, , (Fri Dec 28, 1:23 pm)
Re: TOMOYO Linux Security Goal, Tetsuo Handa, (Sun Dec 30, 1:29 am)
Re: TOMOYO Linux Security Goal, , (Sun Dec 30, 2:28 am)
Re: TOMOYO Linux Security Goal, Casey Schaufler, (Mon Dec 31, 11:27 am)
Re: TOMOYO Linux Security Goal, Pavel Machek, (Sat Dec 29, 8:02 pm)
Re: TOMOYO Linux Security Goal, Serge E. Hallyn, (Fri Dec 28, 11:12 am)
Re: TOMOYO Linux Security Goal, Tetsuo Handa, (Fri Dec 28, 11:43 pm)
Re: TOMOYO Linux Security Goal, Serge E. Hallyn, (Mon Dec 31, 11:17 am)
Re: TOMOYO Linux Security Goal, Tetsuo Handa, (Mon Dec 31, 11:25 am)
Re: TOMOYO Linux Security Goal, Serge E. Hallyn, (Mon Dec 31, 12:17 pm)
speck-geostationary