All of lore.kernel.org
 help / color / mirror / Atom feed
* Re: Selinux kernel patches
@ 2001-02-06 20:28 Pete Loscocco
  2001-02-08 18:41 ` Dale Amon
  0 siblings, 1 reply; 10+ messages in thread
From: Pete Loscocco @ 2001-02-06 20:28 UTC (permalink / raw)
  To: selinux

Joshua Brindle wrote:
> I was wondering if there was any effort on your team of developers to
> get your kernel patches submitted to linus for possible inclusion into
> the standard linux source? And also the utility patches, will you be
> trying to submit them to their authors?

We would like very much for our kernel patches to be considered for
inclusion in a future kernel release. We are working toward that goal.
The real goal is to get features such as we have put in Linux accepted
not only in Linux but in other systems as well. We chose Linux because
it not only would increase the security of a popular system but because
it's open development enables it to be a worked example that could be
applied to other systems as well.

We think that we have a good architecture and that it warrants
consideration. We have put it out not as a complete solution but as
something that should be built upon. Inclusion in the "standard"
sources would really enable a much wider audience to work with the
system, gain experience using the security features, and make the
system better.

As for the utility patches, they have never been the focus of the
work.  We have made changes where we found it necessary or useful, but
have yet to make any serious effort to to address all of the user space
issues. If the architecture were to be adopted by the community, we
would probably reexamine that decision and spend more effort on such
things. Until that happens, we probably won't be looking for our
changes to be included with the utility authors.

Pete Loscocco
Information Assurance Research Office
National Security Agency

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 10+ messages in thread
* Re: Cature the flag (was Re: Selinux kernel patches)
@ 2001-02-09 15:18 paul 
  2001-02-09 16:58 ` Jose Nazario
  0 siblings, 1 reply; 10+ messages in thread
From: paul  @ 2001-02-09 15:18 UTC (permalink / raw)
  To: selinux, Sandy Harris

So what happens when the hackers attack the machines logging packets?  Or what if they just decide to take down the router?

---------- Original Message ----------------------------------
From: Sandy Harris <sandy@storm.ca>
Date: Thu, 08 Feb 2001 21:32:11 -0500

>Dale Amon wrote:
>> 
>> On Tue, Feb 06, 2001 at 03:28:44PM -0500, Pete Loscocco wrote:
>> > We think that we have a good architecture and that it warrants
>> > consideration. ...
>> 
>> Just a wild suggestion. When things are well along and
>> everyone thinks the system is ready, why not put a box
>> out on a public network for a game of "capture the flag"?
>
>The annual Defcon conference (http://www.defcon.org/) has run such
>a contest, on a LAN at the conference, for several years now. Some
>firewall vendors bring machines for use as targets.
> 
>> Offer a free T-shirt "I cracked the NSA" to anyone who
>> succeeds *and* tells precisely how it was done. Set up
>> tests for system cracks both from fully external or from
>> various shell access levels.
>
>In addition to attackers' machines and target machiness, they have
>other machines doing packet logging so attacks can be analysed
>later.
>
>A web search on "defcon capture the flag" will turn up the rules,
>last year's logs and some discussion.
>
>--
>You have received this message because you are subscribed to the selinux list.
>If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
>the words "unsubscribe selinux" without quotes as the message.
>

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 10+ messages in thread
* Re: Cature the flag (was Re: Selinux kernel patches)
@ 2001-02-09 15:33 paul 
  2001-02-09 16:31 ` John Cordani
  2001-02-09 16:56 ` Daniel Harrison
  0 siblings, 2 replies; 10+ messages in thread
From: paul  @ 2001-02-09 15:33 UTC (permalink / raw)
  To: selinux

I have always felt that the best way to test a piece of software is the same way that any scientist would test a hypothesis.  The hypothesis here is that the software is secure.  So in order to test that hypothesis you have to have people that test that software for security holes.

In my opinion, finishing a piece of software and then inviting the whole planet to try and "hack" it for $200 and a free shirt is just not the best way to approach this.  You will end up with people from all over the planet not only attacking the system but also the network, including other systems on the same wire that are gathering packets, routers, and perhaps even the upstream provider.  Sure, you can say that all these are off limits, but people will simply not care as has been shown by these kind of "tests" over and over and over.

What we intend to do at Bladestorm is to integrate all the efforts here into our distribution and conduct a controlled test, where the software is tested by security professionals.  It will be probed and tested thoroughly, we would report our findings, patch, reprobe, and then after that cycle is done we will do a beta.  And the beta would be to put the distribution into environments where the software can be tested.  This way, we can eliminate variables such as routers going down and so forth and really be able to pinpoint holes.

Public stunts like this is more like handing 2,000 people a can opener and telling them all to try to be the first to open a can.  You end up with a mess, and a lot of spilled tomato soup.  It's just not worth it from my vantage point.

---------- Original Message ----------------------------------
From: Sandy Harris <sandy@storm.ca>
Date: Thu, 08 Feb 2001 21:32:11 -0500

>Dale Amon wrote:
>> 
>> On Tue, Feb 06, 2001 at 03:28:44PM -0500, Pete Loscocco wrote:
>> > We think that we have a good architecture and that it warrants
>> > consideration. ...
>> 
>> Just a wild suggestion. When things are well along and
>> everyone thinks the system is ready, why not put a box
>> out on a public network for a game of "capture the flag"?
>
>The annual Defcon conference (http://www.defcon.org/) has run such
>a contest, on a LAN at the conference, for several years now. Some
>firewall vendors bring machines for use as targets.
> 
>> Offer a free T-shirt "I cracked the NSA" to anyone who
>> succeeds *and* tells precisely how it was done. Set up
>> tests for system cracks both from fully external or from
>> various shell access levels.
>
>In addition to attackers' machines and target machiness, they have
>other machines doing packet logging so attacks can be analysed
>later.
>
>A web search on "defcon capture the flag" will turn up the rules,
>last year's logs and some discussion.
>
>--
>You have received this message because you are subscribed to the selinux list.
>If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
>the words "unsubscribe selinux" without quotes as the message.
>

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 10+ messages in thread
* RE: Cature the flag (was Re: Selinux kernel patches)
@ 2001-02-09 16:54 Ellis, Wes
  0 siblings, 0 replies; 10+ messages in thread
From: Ellis, Wes @ 2001-02-09 16:54 UTC (permalink / raw)
  To: 'selinux@tycho.nsa.gov'

Then this is another vulnerability, and would need to be addressed, a
machine is not just itself, but any other machines attached to it, and this
is most often were I have personally found weaknesses in audits.

-----Original Message-----
From: paul [mailto:paul@bladestorm.com]
Sent: Friday, February 09, 2001 9:18 AM
To: selinux@tycho.nsa.gov; Sandy Harris
Subject: Re: Cature the flag (was Re: Selinux kernel patches)


So what happens when the hackers attack the machines logging packets?  Or
what if they just decide to take down the router?

---------- Original Message ----------------------------------
From: Sandy Harris <sandy@storm.ca>
Date: Thu, 08 Feb 2001 21:32:11 -0500

>Dale Amon wrote:
>> 
>> On Tue, Feb 06, 2001 at 03:28:44PM -0500, Pete Loscocco wrote:
>> > We think that we have a good architecture and that it warrants
>> > consideration. ...
>> 
>> Just a wild suggestion. When things are well along and
>> everyone thinks the system is ready, why not put a box
>> out on a public network for a game of "capture the flag"?
>
>The annual Defcon conference (http://www.defcon.org/) has run such
>a contest, on a LAN at the conference, for several years now. Some
>firewall vendors bring machines for use as targets.
> 
>> Offer a free T-shirt "I cracked the NSA" to anyone who
>> succeeds *and* tells precisely how it was done. Set up
>> tests for system cracks both from fully external or from
>> various shell access levels.
>
>In addition to attackers' machines and target machiness, they have
>other machines doing packet logging so attacks can be analysed
>later.
>
>A web search on "defcon capture the flag" will turn up the rules,
>last year's logs and some discussion.
>
>--
>You have received this message because you are subscribed to the selinux
list.
>If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov
with
>the words "unsubscribe selinux" without quotes as the message.
>

--
You have received this message because you are subscribed to the selinux
list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov
with
the words "unsubscribe selinux" without quotes as the message.

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2001-02-09 17:02 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2001-02-06 20:28 Selinux kernel patches Pete Loscocco
2001-02-08 18:41 ` Dale Amon
2001-02-08 21:37   ` Christopher McCrory
2001-02-09  2:32   ` Cature the flag (was Re: Selinux kernel patches) Sandy Harris
  -- strict thread matches above, loose matches on Subject: below --
2001-02-09 15:18 paul 
2001-02-09 16:58 ` Jose Nazario
2001-02-09 15:33 paul 
2001-02-09 16:31 ` John Cordani
2001-02-09 16:56 ` Daniel Harrison
2001-02-09 16:54 Ellis, Wes

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.