From: Corey Bryant <coreyb@linux.vnet.ibm.com>
To: kernel-hardening@lists.openwall.com
Cc: Kees Cook <keescook@chromium.org>,
Julia Lawall <julia.lawall@lip6.fr>,
James Morris <jmorris@namei.org>, Theodore Tso <tytso@google.com>,
Paul Moore <pmoore@redhat.com>, Eric Paris <eparis@redhat.com>,
Tyler Hicks <tyhicks@canonical.com>,
zohar@us.ibm.com, john.johansen@canonical.com,
Dan Carpenter <dan.carpenter@oracle.com>,
Fengguang Wu <fengguang.wu@intel.com>
Subject: Re: [kernel-hardening] Re: Linux Security Workgroup
Date: Mon, 08 Oct 2012 13:52:02 -0400 [thread overview]
Message-ID: <507312C2.3070704@linux.vnet.ibm.com> (raw)
In-Reply-To: <CAGXu5jK-=EZ8tmkTZ8eESAFjt9OJoPOOcKTXfmREy4ZMuB13SQ@mail.gmail.com>
On 10/02/2012 06:17 PM, Kees Cook wrote:
> On Tue, Oct 2, 2012 at 9:44 AM, Corey Bryant <coreyb@linux.vnet.ibm.com> wrote:
>>
>>
>> On 10/02/2012 12:23 PM, Kees Cook wrote:
>>>
>>> On Thu, Sep 27, 2012 at 12:26 PM, Corey Bryant
>>> <coreyb@linux.vnet.ibm.com> wrote:
>>>>
>>>> At the Linux Security Summit we began discussing the Linux Security
>>>> Workgroup and some of the efforts that we can focus on.
>>>>
>>>> The charter of the workgroup is to provide on-going security
>>>> verification of Linux kernel subsystems in order to assist in securing
>>>> the
>>>> Linux Kernel and maintain trust and confidence in the security of the
>>>> Linux
>>>> ecosystem.
>>>>
>>>> This may include, but is not limited to, topics such as tooling to assist
>>>> in
>>>> securing the Linux Kernel, verification and testing of critical
>>>> subsystems
>>>> for vulnerabilities, security improvements for build tools, and providing
>>>> guidance for maintaining subsystem security.
>>>
>>>
>>> Thanks for getting this rolling!
>>>
>>> What are the next steps? Does it make sense to try to gather a list of
>>> active projects to try and see where things currently stand? (i.e who
>>> is actively running smatch, trinity, etc?) Or to call attention to a
>>> specific subsystem that needs direct auditing (e.g. KVM)?
>>>
>>> -Kees
>>>
>>
>> No problem, thanks for the input!
>>
>> I think having a list of active projects is a good place to start.
>
> I know Dan Carpenter is running smatch, as well as Fengguang Wu.
> Getting details on which trees are being scanned would be good.
>
> I know Fengguang Wu is running trinity too.
>
> There is a collection of coccinelle scripts in the tree, but I'm not
> sure if/when those are getting run by anyone. Julia, do you know if
> those are being regularly run?
>
>> Perhaps we can also add desired projects to this list, and if anyone has
>> cycles to cover a project they can put their name to the project.
>
> I was keeping a list of potential hardening work here:
> https://wiki.ubuntu.com/SecurityTeam/Roadmap/KernelHardening#Upstream_Hardening
> some of it is out of date.
>
>> I'm personally trying to get time allocated to work on KVM fuzzing and/or
>> static analysis in 2013.
>
> Sounds good.
>
>> A wiki probably makes sense for the list. Google sites has wikis. I can
>> start one there unless there are other ideas.
>
> Kernel.org hosts wikis as well, and James Morris already has
> http://kernsec.org/. Perhaps we can use that? James, would this be
> something you'd be okay with?
Here's a start on the wiki. There's not really a whole lot on it other
than what we've discussed on the list, but it's a start. Comments and
updates are very much welcome.
http://kernsec.org/wiki/index.php/Linux_Security_Workgroup
A couple of questions:
* What should the work group's scope be? The charter mentions " ...
on-going security verification of Linux kernel subsystems ... ". I was
thinking it would focus more on items like: fuzzing, static analysis,
education for reviewing code, tooling/build security enhancements. But
I have a feeling it will start to include Kernel development projects too.
* Where should we document inactive, but desired, projects? I know
Kees has https://wiki.ubuntu.com/SecurityTeam/Roadmap/KernelHardening
but I'm wondering if it makes sense to keep track of work items on the
same wiki.
--
Regards,
Corey Bryant
next prev parent reply other threads:[~2012-10-08 17:52 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-09-27 19:26 [kernel-hardening] Linux Security Workgroup Corey Bryant
2012-10-02 16:23 ` [kernel-hardening] " Kees Cook
2012-10-02 16:44 ` Corey Bryant
2012-10-02 22:17 ` Kees Cook
2012-10-03 5:38 ` Julia Lawall
2012-10-03 5:45 ` Dan Carpenter
2012-10-03 21:59 ` Corey Bryant
2012-10-04 5:29 ` James Morris
2012-10-08 17:52 ` Corey Bryant [this message]
2012-10-08 20:00 ` Kees Cook
2012-10-08 20:59 ` Corey Bryant
2012-10-08 21:11 ` Paul Moore
2012-10-08 21:49 ` Kees Cook
2012-10-09 14:07 ` Corey Bryant
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=507312C2.3070704@linux.vnet.ibm.com \
--to=coreyb@linux.vnet.ibm.com \
--cc=dan.carpenter@oracle.com \
--cc=eparis@redhat.com \
--cc=fengguang.wu@intel.com \
--cc=jmorris@namei.org \
--cc=john.johansen@canonical.com \
--cc=julia.lawall@lip6.fr \
--cc=keescook@chromium.org \
--cc=kernel-hardening@lists.openwall.com \
--cc=pmoore@redhat.com \
--cc=tyhicks@canonical.com \
--cc=tytso@google.com \
--cc=zohar@us.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.