A Comparative Analysis of Linux Mandatory Access Control Policy Enforcement Mechanisms
Brennon Brimhall, Justin M. Garrard, Christopher De La Garza, Joel Coffman · 2023
Unix---and by extension, Linux---traditionally uses a discretionary access control (DAC) paradigm. DAC mechanisms are decentralized by design, which makes it difficult to audit the security of a computer system. Furthermore, Unix systems have the concept of a root user who can bypass any DAC policies in place. These issues led to the development of mandatory access control (MAC) mechanisms, such as AppArmor, Security-Enhanced Linux (SELinux), and eBPF.