ASPGen: an Automatic Security Policy Generating Framework for AppArmor

Yun Li, Chenlin Huang, Yuan Lu, Yan Ding, Hua Cheng · 2020

The security of the operating system has always been the basis of information systems. Several security frameworks have been proposed to enhance the security of the operating system, such as SELinux and AppArmor. However, the major drawback of these solutions is the complexity of the security policy configuration in which strong professionalism is required. Therefore, there are many related studies on optimizing the process of configuring security policies, but so far the involvement of security experts is still required. In this paper, we aim to further optimize the AppArmor's security policy generating process and propose ASPGen, which is a novel framework for generating AppArmor security policies automatically. ASPGen can autogenerate security policy with the least privilege and RBAC (Role-Based Access Control) for applications, and effectively alleviate the complexity and subjectivity in manually configuring AppArmor's security policy, as well as the security threats that result from the improper policy. We implement the prototype of ASPGen in Ubuntu 16.04. Unlike previous approaches, ASPGen does not depend on experts after the expert system is built. In our experimental evaluation, several typical applications are chosen and generate their AppArmor security policies with ASPGen. The completeness and precision of the generated policies are evaluated and a case of mysql-server is thoroughly analyzed by comparing the default AppArmor security policies with the policies generated by ASPGen. The evaluation demonstrates that the policy generated by ASPGen is complete, precise, and fine-grained, even without expert intervention. Our contribution can be further improved with a more general and intelligent security policy generating mechanism and is being extended to support other security frameworks including SELinux and SEAndroid.

Read the paper · More papers on PaperTik