RSBAC - a framework for enhanced Linux system security

Marek Jawurek · 2006

Operating systems traditionally bring their own means of protection against any kind of threats. But often the system’s security is based on an evolved composition of different projects and tools, historically grown with their operating system, ensuring and controlling system security. Therefore only rarely a coherent security solution is provided by the system. This existing structure of security suffers from different problems and inconsistencies, caused by its evolution, and often lacks universality due to bad or shortsighted design decisions in its history. The RSBAC framework is focused on the elimination of these drawbacks in Linux kernels and has been designed this way from its start. It introduces a modular framework to allow ne-gr ained access control enabling system administrators to compose a system using a combination of the preferred security models. This paper presents the RSBAC approach and outlines RSBAC’s concept of integration into the Linux kernel. Furthermore, this work presents similar solutions to kernel security and discusses the advantages and disadvantages of RSBAC to those other solutions.

Read the paper · More papers on PaperTik