From: zohar@linux.vnet.ibm.com (Mimi Zohar)
To: linux-security-module@vger.kernel.org
Subject: [Linux-ima-devel] [RFC PATCH 1/5] ima: extend clone() with IMA namespace support
Date: Mon, 31 Jul 2017 07:31:58 -0400 [thread overview]
Message-ID: <1501500718.9230.85.camel@linux.vnet.ibm.com> (raw)
In-Reply-To: <TU4PR84MB03025BC4B8DEC44A0D63A298FFBF0@TU4PR84MB0302.NAMPRD84.PROD.OUTLOOK.COM>
On Fri, 2017-07-28 at 14:19 +0000, Magalhaes, Guilherme (Brazil R&D-
CL) wrote:
> > > Each measurement entry in the list could have new fields to identify
> > > the namespace. Since the namespaces can be reused, a timestamp or
> > > others fields could be added to uniquely identify the namespace id.
> >
> > The more fields included in the measurement list, the more
> > measurements will be added to the measurement list. Wouldn't it be
> > enough to know that a certain file has been accessed/executed on the
> > system and base any analytics/forensics on the IMA-audit data.
>
> With the recursive application of policy through the namespace hierarchy,
> a measurement added to the parent namespace could be misleading since
> the file pathname makes sense in the current namespace but possibly not
> for the parent namespace.
Fair enough.
> This is the reason why I believe some new field
> might be needed in the IMA template format to indicate or uniquely
> identify the namespace.
I would probably include information to uniquely identify the file
(eg. UUID, mountpoint), not the namespace.
?
Mimi
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
WARNING: multiple messages have this Message-ID (diff)
From: Mimi Zohar <zohar@linux.vnet.ibm.com>
To: "Magalhaes,
Guilherme (Brazil R&D-CL)" <guilherme.magalhaes@hpe.com>,
"Serge E. Hallyn" <serge@hallyn.com>
Cc: Mehmet Kayaalp <mkayaalp@cs.binghamton.edu>,
Yuqiong Sun <sunyuqiong1988@gmail.com>,
containers <containers@lists.linux-foundation.org>,
linux-kernel <linux-kernel@vger.kernel.org>,
David Safford <david.safford@ge.com>,
James Bottomley <James.Bottomley@HansenPartnership.com>,
linux-security-module <linux-security-module@vger.kernel.org>,
ima-devel <linux-ima-devel@lists.sourceforge.net>,
Yuqiong Sun <suny@us.ibm.com>
Subject: Re: [Linux-ima-devel] [RFC PATCH 1/5] ima: extend clone() with IMA namespace support
Date: Mon, 31 Jul 2017 07:31:58 -0400 [thread overview]
Message-ID: <1501500718.9230.85.camel@linux.vnet.ibm.com> (raw)
In-Reply-To: <TU4PR84MB03025BC4B8DEC44A0D63A298FFBF0@TU4PR84MB0302.NAMPRD84.PROD.OUTLOOK.COM>
On Fri, 2017-07-28 at 14:19 +0000, Magalhaes, Guilherme (Brazil R&D-
CL) wrote:
> > > Each measurement entry in the list could have new fields to identify
> > > the namespace. Since the namespaces can be reused, a timestamp or
> > > others fields could be added to uniquely identify the namespace id.
> >
> > The more fields included in the measurement list, the more
> > measurements will be added to the measurement list. Wouldn't it be
> > enough to know that a certain file has been accessed/executed on the
> > system and base any analytics/forensics on the IMA-audit data.
>
> With the recursive application of policy through the namespace hierarchy,
> a measurement added to the parent namespace could be misleading since
> the file pathname makes sense in the current namespace but possibly not
> for the parent namespace.
Fair enough.
> This is the reason why I believe some new field
> might be needed in the IMA template format to indicate or uniquely
> identify the namespace.
I would probably include information to uniquely identify the file
(eg. UUID, mountpoint), not the namespace.
Mimi
next prev parent reply other threads:[~2017-07-31 11:31 UTC|newest]
Thread overview: 131+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-07-20 22:50 [RFC PATCH 0/5] ima: namespacing IMA audit messages Mehmet Kayaalp
2017-07-20 22:50 ` Mehmet Kayaalp
2017-07-20 22:50 ` [RFC PATCH 1/5] ima: extend clone() with IMA namespace support Mehmet Kayaalp
2017-07-20 22:50 ` Mehmet Kayaalp
[not found] ` <20170720225033.21298-2-mkayaalp-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-07-25 17:53 ` Serge E. Hallyn
2017-07-25 17:53 ` Serge E. Hallyn
2017-07-25 17:53 ` Serge E. Hallyn
2017-07-25 18:49 ` James Bottomley
2017-07-25 18:49 ` James Bottomley
[not found] ` <1501008554.3689.30.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
2017-07-25 19:04 ` Serge E. Hallyn
2017-07-25 19:04 ` Serge E. Hallyn
2017-07-25 19:04 ` Serge E. Hallyn
2017-07-25 19:08 ` James Bottomley
2017-07-25 19:08 ` James Bottomley
2017-07-25 19:48 ` Mimi Zohar
2017-07-25 19:48 ` Mimi Zohar
[not found] ` <1501012082.27413.17.camel-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-07-25 20:11 ` Stefan Berger
2017-07-25 20:11 ` Stefan Berger
2017-07-25 20:11 ` Stefan Berger
[not found] ` <645db815-7773-e351-5db7-89f38cd88c3d-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-07-25 20:46 ` Serge E. Hallyn
2017-07-25 20:46 ` Serge E. Hallyn
2017-07-25 20:46 ` Serge E. Hallyn
[not found] ` <20170725204622.GA4969-7LNsyQBKDXoIagZqoN9o3w@public.gmane.org>
2017-07-25 20:57 ` Mimi Zohar
2017-07-25 20:57 ` Mimi Zohar
2017-07-25 20:57 ` Mimi Zohar
2017-07-25 21:08 ` Serge E. Hallyn
2017-07-25 21:08 ` Serge E. Hallyn
[not found] ` <20170725210801.GA5628-7LNsyQBKDXoIagZqoN9o3w@public.gmane.org>
2017-07-25 21:28 ` Mimi Zohar
2017-07-25 21:28 ` Mimi Zohar
2017-07-25 21:28 ` Mimi Zohar
[not found] ` <1501018134.27413.66.camel-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-07-27 12:51 ` [Linux-ima-devel] " Magalhaes, Guilherme (Brazil R&D-CL)
2017-07-27 12:51 ` Magalhaes, Guilherme (Brazil R&D-CL)
2017-07-27 12:51 ` Magalhaes, Guilherme (Brazil R&D-CL)
2017-07-27 14:39 ` Mimi Zohar
2017-07-27 14:39 ` Mimi Zohar
2017-07-27 17:18 ` Magalhaes, Guilherme (Brazil R&D-CL)
2017-07-27 17:18 ` Magalhaes, Guilherme (Brazil R&D-CL)
[not found] ` <TU4PR84MB03025AD26718A173FB3E3F94FFBE0-cn0wsXH2uUebani3oaRudNicc1VoeDReZmpNikb/MY7jO8Y7rvWZVA@public.gmane.org>
2017-07-27 17:49 ` Stefan Berger
2017-07-27 17:49 ` Stefan Berger
2017-07-27 17:49 ` Stefan Berger
2017-07-27 19:39 ` Magalhaes, Guilherme (Brazil R&D-CL)
2017-07-27 19:39 ` Magalhaes, Guilherme (Brazil R&D-CL)
[not found] ` <TU4PR84MB030243E7071B5A7455334886FFBE0-cn0wsXH2uUebani3oaRudNicc1VoeDReZmpNikb/MY7jO8Y7rvWZVA@public.gmane.org>
2017-07-27 20:51 ` Stefan Berger
2017-07-27 20:51 ` Stefan Berger
2017-07-27 20:51 ` Stefan Berger
[not found] ` <3c3d8594-9958-5f53-ec0b-f33c36967f95-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-07-27 19:39 ` Magalhaes, Guilherme (Brazil R&D-CL)
[not found] ` <1501166369.28419.171.camel-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-07-27 17:18 ` Magalhaes, Guilherme (Brazil R&D-CL)
2017-07-28 14:19 ` Magalhaes, Guilherme (Brazil R&D-CL)
2017-07-28 14:19 ` Magalhaes, Guilherme (Brazil R&D-CL)
2017-07-28 14:19 ` Magalhaes, Guilherme (Brazil R&D-CL)
[not found] ` <TU4PR84MB03025BC4B8DEC44A0D63A298FFBF0-cn0wsXH2uUebani3oaRudNicc1VoeDReZmpNikb/MY7jO8Y7rvWZVA@public.gmane.org>
2017-07-31 11:31 ` Mimi Zohar
2017-07-31 11:31 ` Mimi Zohar [this message]
2017-07-31 11:31 ` Mimi Zohar
[not found] ` <TU4PR84MB03021F7FDF1B89ECAA8F7FFFFFBE0-cn0wsXH2uUebani3oaRudNicc1VoeDReZmpNikb/MY7jO8Y7rvWZVA@public.gmane.org>
2017-07-27 14:39 ` Mimi Zohar
[not found] ` <1501016277.27413.50.camel-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-07-25 21:08 ` Serge E. Hallyn
2017-07-25 21:35 ` Stefan Berger
2017-07-25 21:35 ` Stefan Berger
2017-07-25 21:35 ` Stefan Berger
2018-03-08 14:04 ` Stefan Berger
2018-03-08 14:04 ` Stefan Berger
2018-03-08 14:04 ` Stefan Berger
2018-03-09 2:59 ` Serge E. Hallyn
2018-03-09 2:59 ` Serge E. Hallyn
[not found] ` <20180309025942.GA15295-7LNsyQBKDXoIagZqoN9o3w@public.gmane.org>
2018-03-09 13:52 ` Stefan Berger
2018-03-09 13:52 ` Stefan Berger
2018-03-09 13:52 ` Stefan Berger
[not found] ` <ec137677-34f8-df91-0d1c-6c6d6c951496-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2018-03-11 22:58 ` James Morris
2018-03-11 22:58 ` James Morris
2018-03-11 22:58 ` James Morris
[not found] ` <alpine.LRH.2.21.1803120953310.26512-gx6/JNMH7DfYtjvyW6yDsg@public.gmane.org>
2018-03-13 18:02 ` Stefan Berger
2018-03-13 18:02 ` Stefan Berger
2018-03-13 18:02 ` Stefan Berger
[not found] ` <c39350db-046f-ea70-15e4-210884548b1e-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2018-03-13 21:51 ` James Morris
2018-03-13 21:51 ` James Morris
2018-03-13 21:51 ` James Morris
[not found] ` <97839865-b0ab-8e5d-114e-0603ef2edf6f-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2018-03-09 2:59 ` Serge E. Hallyn
2017-07-25 20:31 ` James Bottomley
2017-07-25 20:31 ` James Bottomley
2017-07-25 20:31 ` James Bottomley
[not found] ` <1501014695.3689.41.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
2017-07-25 20:47 ` Mimi Zohar
2017-07-25 20:47 ` Mimi Zohar
2017-07-25 20:47 ` Mimi Zohar
[not found] ` <1501009739.3689.33.camel-d9PhHud1JfjCXq6kfMZ53/egYHeGw8Jk@public.gmane.org>
2017-07-25 19:48 ` Mimi Zohar
[not found] ` <20170725190406.GA1883-7LNsyQBKDXoIagZqoN9o3w@public.gmane.org>
2017-07-25 19:08 ` James Bottomley
[not found] ` <20170725175317.GA727-7LNsyQBKDXoIagZqoN9o3w@public.gmane.org>
2017-07-25 18:49 ` James Bottomley
2018-03-08 13:39 ` Stefan Berger
2018-03-08 13:39 ` Stefan Berger
2018-03-08 13:39 ` Stefan Berger
[not found] ` <2fac8414-6957-1fce-6b40-ad4b687ca83c-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2018-03-08 20:19 ` Serge E. Hallyn
2018-03-08 20:19 ` Serge E. Hallyn
2018-03-08 20:19 ` Serge E. Hallyn
[not found] ` <20180308201931.GA6462-7LNsyQBKDXoIagZqoN9o3w@public.gmane.org>
2018-03-08 22:53 ` Stefan Berger
2018-03-08 23:31 ` Serge E. Hallyn
2018-03-08 23:31 ` Serge E. Hallyn
[not found] ` <a6ef5679-6aef-21de-7cdb-48e8af83f874-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2018-03-08 23:31 ` Serge E. Hallyn
2017-07-20 22:50 ` [RFC PATCH 2/5] ima: Add ns_status for storing namespaced iint data Mehmet Kayaalp
2017-07-20 22:50 ` Mehmet Kayaalp
[not found] ` <20170720225033.21298-3-mkayaalp-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-07-25 19:43 ` Serge E. Hallyn
2017-07-25 19:43 ` Serge E. Hallyn
2017-07-25 19:43 ` Serge E. Hallyn
[not found] ` <20170725194315.GA2397-7LNsyQBKDXoIagZqoN9o3w@public.gmane.org>
2017-07-25 20:15 ` Mimi Zohar
2017-07-25 20:15 ` Mimi Zohar
2017-07-25 20:15 ` Mimi Zohar
[not found] ` <1501013725.27413.27.camel-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-07-25 20:25 ` Stefan Berger
2017-07-25 20:25 ` Stefan Berger
2017-07-25 20:25 ` Stefan Berger
2017-07-25 20:49 ` Serge E. Hallyn
2017-07-25 20:49 ` Serge E. Hallyn
2017-07-25 20:49 ` Serge E. Hallyn
2017-08-11 15:00 ` Stefan Berger
2017-08-11 15:00 ` Stefan Berger
2017-08-11 15:00 ` Stefan Berger
2017-07-20 22:50 ` [RFC PATCH 3/5] ima: mamespace audit status flags Mehmet Kayaalp
2017-07-20 22:50 ` Mehmet Kayaalp
2017-08-01 17:17 ` Tycho Andersen
2017-08-01 17:17 ` Tycho Andersen
2017-08-01 17:25 ` Mehmet Kayaalp
2017-08-01 17:25 ` Mehmet Kayaalp
2017-08-02 21:48 ` Tycho Andersen
2017-08-02 21:48 ` Tycho Andersen
2017-08-01 17:25 ` Mehmet Kayaalp
[not found] ` <20170720225033.21298-4-mkayaalp-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-08-01 17:17 ` Tycho Andersen via Containers
[not found] ` <20170720225033.21298-1-mkayaalp-23VcF4HTsmIX0ybBhKVfKdBPR1lH4CV8@public.gmane.org>
2017-07-20 22:50 ` [RFC PATCH 1/5] ima: extend clone() with IMA namespace support Mehmet Kayaalp
2017-07-20 22:50 ` [RFC PATCH 2/5] ima: Add ns_status for storing namespaced iint data Mehmet Kayaalp
2017-07-20 22:50 ` [RFC PATCH 3/5] ima: mamespace audit status flags Mehmet Kayaalp
2017-07-20 22:50 ` [RFC PATCH 4/5] ima: differentiate auditing policy rules from "audit" actions Mehmet Kayaalp
2017-07-20 22:50 ` Mehmet Kayaalp
2017-07-20 22:50 ` Mehmet Kayaalp
2017-07-20 22:50 ` [RFC PATCH 5/5] ima: Add ns_mnt, dev, ino fields to IMA audit measurement msgs Mehmet Kayaalp
2017-07-20 22:50 ` Mehmet Kayaalp
2017-07-20 22:50 ` Mehmet Kayaalp
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1501500718.9230.85.camel@linux.vnet.ibm.com \
--to=zohar@linux.vnet.ibm.com \
--cc=linux-security-module@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.