SEGrapher: Visualization-based SELinux policy analysis
Said Marouf, Mohamed Elemam Shehab · 2011
Performing SELinux policy analyses can be difficult due to the complexity of the policy language and the sheer number of policy rules and attributes involved. For example, the default policy on most SELinux-enabled systems has over 1; 500; 000 flat rules, involving over 1; 780 types. Simple analyses between types can result in a large amount of data, which is poorly presented to administrators in existing analysis tools. We propose and implement a policy analysis tool “SEGrapher” that addresses the above challenges. SEGrapher visually presents analysis results as a simplified directed graph, where nodes are types, and edges are corresponding policy rules between types. Graphs are generated via a proposed clustering algorithm that clusters types based on their accesses. Clusters provide an abstraction layer that removes undesired data, and focuses on analysis attributes specified by the administrator.