All of lore.kernel.org
 help / color / mirror / Atom feed
From: "cto@itechfrontiers.com" <cto@itechfrontiers.com>
To: Sanjai Narain <narain@research.telcordia.com>
Cc: selinux@tycho.nsa.gov
Subject: Re: SELinux and Stuxnet
Date: Tue, 22 Feb 2011 11:53:40 -0500	[thread overview]
Message-ID: <4D63EA14.2080701@itechfrontiers.com> (raw)
In-Reply-To: <4D4604DB.3060402@itechfrontiers.com>

On 1/30/2011 7:39 PM, cto@itechfrontiers.com wrote:
> Hello,
>
> Stuxnet is a Windows Worm, and SELinux is Mandatory Access Control for
> Linux
>
> on Linux SELinux can reduce the impact of such worms if targeting Linux
> boxes, but it is not a preemptive mechanism for not having any kind of
> compromise due to any vulnerability, Although if you protect your system
> and targeted processes you may have reach the goal of containing the
> impact of possible compromises
>
>
> Best,
>
> Patrick K.
>
> On 1/30/2011 5:20 PM, Sanjai Narain wrote:
>> Has there been thinking on whether SELinux-hardened machines can avoid
>> the spread of Stuxnet-like worms? Thanks. --Sanjai
>>
>
>
> --
> This message was distributed to subscribers of the selinux mailing list.
> If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov
> with
> the words "unsubscribe selinux" without quotes as the message.

Sanjai,

SELinux is Mandatory Access Control for Linux

Stuxnet only compromises Windows, SCADA and PLC 7 systems (Siemens systems)

it is a worm, for a worm to compromise a system you need to have certain 
vulnerabilities

It cannot compromise Linux (the same way); as that worm has been 
designed for particular purposes and taking advantages of Windows 
vulnerabilities

If you mean protecting a network using Linux front ends or inline 
systems Like IPS systems that's another story which is irrelevant to 
SELINUX actually  (although an IPS system -Intrusion Prevention system- 
on Linux can take advantages of SELINUX)

in brief , theoretically in case of a worm for Linux, it could be 
contained if SELINUX is effectively used.

in practice Stuxnet is for Windows

Best,

Patrick K.


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2011-02-22 16:53 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-01-26 18:16 SeLinux Policy design question Ger Lawlor (gelawlor)
2011-01-26 20:16 ` Dominick Grift
2011-01-26 20:35   ` Ethan Heidrick
2011-01-30 22:20 ` SELinux and Stuxnet Sanjai Narain
2011-01-31  0:39   ` cto
2011-02-22 16:53     ` cto [this message]
2011-02-22 17:19       ` Sanjai Narain
2011-02-22 17:43         ` cto
2011-02-22 17:54           ` cto
2011-02-22 21:47             ` Ethan Heidrick
2011-02-22 22:13               ` cto
2011-02-23  2:54                 ` Ethan Heidrick
2011-02-23  3:41                   ` cto

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4D63EA14.2080701@itechfrontiers.com \
    --to=cto@itechfrontiers.com \
    --cc=narain@research.telcordia.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.