All of lore.kernel.org
 help / color / mirror / Atom feed
* Security policy analysis
@ 2001-10-09 19:49 Frank Mayer
  2001-10-09 23:32 ` John Scroggins
                   ` (2 more replies)
  0 siblings, 3 replies; 16+ messages in thread
From: Frank Mayer @ 2001-10-09 19:49 UTC (permalink / raw)
  To: SELinux

We're looking at SE Linux as a building block upon which we can build
protected applications of various types.  One of the issues we are working
through include identifying a core "baseline" Linux configuration and
associated SE Linux policy for that baseline.  One means of doing this is to
examine sample policies (like the one distributed with the source).  If
anyone else is doing similar things, we'd like to like to hear more.  Also,
is anyone else working on alternative sample policies, especially for a core
Linux configuration?

We also find ourselves incrementally building tools to analyze policy.conf
files (e.g., show all types with a given attribute, show all rules that
involve a given type/attribute).  Essentially to help reverse engineer and
analyze the intent of a given policy.  We have some capabilities built, and
are writing additional ones as time and need allow (essentially by borrowing
the lex/yacc source from checkpolicy, and building our own policy database
and analysis logic).  Is anyone else building similar tools?  We'd be happy
to share our source incrementally with members of the list as we build new
capabilities if anyone is interested.

PS- Please reply to the mail list; we'd like to start open discussions of
policy analysis and development.

Regards,
Frank Mayer
mayerf@tresys.com
Tresys Technology



--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 16+ messages in thread

end of thread, other threads:[~2001-10-10 21:11 UTC | newest]

Thread overview: 16+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2001-10-09 19:49 Security policy analysis Frank Mayer
2001-10-09 23:32 ` John Scroggins
2001-10-10  6:05 ` Interested in Reserach work Ravi Prakash B.V.
2001-10-10 12:26 ` Security policy analysis Stephen Smalley
2001-10-10 14:23   ` ipv6
2001-10-10 14:39     ` Frank Mayer
2001-10-10 12:50       ` Julien Palardy
2001-10-10 17:52     ` EZ
2001-10-10 19:40       ` ipv6
2001-10-10 17:02   ` Jon Crowley
2001-10-10 18:09     ` Frank Mayer
2001-10-10 19:32       ` Stephen Smalley
2001-10-10 20:11         ` Frank Mayer
2001-10-10 21:11           ` Frank Mayer
2001-10-10 20:11         ` Frank Mayer
2001-10-10 19:04     ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.