* LSM performance measurement
@ 2022-07-06 15:22 Dmitry Kasatkin
2022-07-06 15:39 ` Casey Schaufler
2022-07-06 15:47 ` Igor Zhbanov
0 siblings, 2 replies; 5+ messages in thread
From: Dmitry Kasatkin @ 2022-07-06 15:22 UTC (permalink / raw)
To: linux-security-module
Hi,
Could anybody suggest a good approach/test suite to measure LSMs
runtime overheads?
--
Thanks,
Dmitry
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: LSM performance measurement
2022-07-06 15:22 LSM performance measurement Dmitry Kasatkin
@ 2022-07-06 15:39 ` Casey Schaufler
2022-07-07 8:54 ` Dmitry Kasatkin
2022-07-06 15:47 ` Igor Zhbanov
1 sibling, 1 reply; 5+ messages in thread
From: Casey Schaufler @ 2022-07-06 15:39 UTC (permalink / raw)
To: Dmitry Kasatkin, linux-security-module; +Cc: casey
On 7/6/2022 8:22 AM, Dmitry Kasatkin wrote:
> Hi,
>
> Could anybody suggest a good approach/test suite to measure LSMs
> runtime overheads?
I have used LMbench, ltp and kernel builds when checking the
overhead on the LSM stacking work. I have also tried timing the
SELinux, audit and Smack testsuites, but they all have built in
delays that make performance numbers questionable. Be sure to
include network throughput and latency measurements if you're
looking at SELinux and/or Smack. Also be sure that you have
meaningful policy loaded, that you're consistent with how IMA
is used, and that you know how your audit limits are configured.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: LSM performance measurement
2022-07-06 15:22 LSM performance measurement Dmitry Kasatkin
2022-07-06 15:39 ` Casey Schaufler
@ 2022-07-06 15:47 ` Igor Zhbanov
2022-07-07 8:54 ` Dmitry Kasatkin
1 sibling, 1 reply; 5+ messages in thread
From: Igor Zhbanov @ 2022-07-06 15:47 UTC (permalink / raw)
To: Dmitry Kasatkin, linux-security-module
Hi Dmitry,
On 06.07.2022 18:22, Dmitry Kasatkin wrote:
> Could anybody suggest a good approach/test suite to measure LSMs
> runtime overheads?
There are a couple of old articles on the same subject.
So, you can get some ideas from there:
- Evaluation of Performance of Secure OS Using Performance Evaluation
Mechanism of LSM-Based LSMPMON
http://www.swlab.cs.okayama-u.ac.jp/~yamauchi/research/sectech2010_yamamoto.pdf
- Analyzing the Overhead of Filesystem Protection Using Linux Security Modules
https://arxiv.org/pdf/2101.11611
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: LSM performance measurement
2022-07-06 15:39 ` Casey Schaufler
@ 2022-07-07 8:54 ` Dmitry Kasatkin
0 siblings, 0 replies; 5+ messages in thread
From: Dmitry Kasatkin @ 2022-07-07 8:54 UTC (permalink / raw)
To: Casey Schaufler; +Cc: linux-security-module
Hi Casey,
Thanks. Those certainly sound familiar..
Will have a look.
-Dmitry
On Wed, Jul 6, 2022 at 6:39 PM Casey Schaufler <casey@schaufler-ca.com> wrote:
>
> On 7/6/2022 8:22 AM, Dmitry Kasatkin wrote:
> > Hi,
> >
> > Could anybody suggest a good approach/test suite to measure LSMs
> > runtime overheads?
>
> I have used LMbench, ltp and kernel builds when checking the
> overhead on the LSM stacking work. I have also tried timing the
> SELinux, audit and Smack testsuites, but they all have built in
> delays that make performance numbers questionable. Be sure to
> include network throughput and latency measurements if you're
> looking at SELinux and/or Smack. Also be sure that you have
> meaningful policy loaded, that you're consistent with how IMA
> is used, and that you know how your audit limits are configured.
>
--
Thanks,
Dmitry
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: LSM performance measurement
2022-07-06 15:47 ` Igor Zhbanov
@ 2022-07-07 8:54 ` Dmitry Kasatkin
0 siblings, 0 replies; 5+ messages in thread
From: Dmitry Kasatkin @ 2022-07-07 8:54 UTC (permalink / raw)
To: Igor Zhbanov; +Cc: linux-security-module
On Wed, Jul 6, 2022 at 6:47 PM Igor Zhbanov <izh1979@gmail.com> wrote:
>
> Hi Dmitry,
>
> On 06.07.2022 18:22, Dmitry Kasatkin wrote:
> > Could anybody suggest a good approach/test suite to measure LSMs
> > runtime overheads?
>
> There are a couple of old articles on the same subject.
> So, you can get some ideas from there:
> - Evaluation of Performance of Secure OS Using Performance Evaluation
> Mechanism of LSM-Based LSMPMON
> http://www.swlab.cs.okayama-u.ac.jp/~yamauchi/research/sectech2010_yamamoto.pdf
> - Analyzing the Overhead of Filesystem Protection Using Linux Security Modules
> https://arxiv.org/pdf/2101.11611
>
Hello,
Thanks. Google also gave me that second article.
Seems to be useful to read.
--
Thanks,
Dmitry
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2022-07-07 8:55 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-07-06 15:22 LSM performance measurement Dmitry Kasatkin
2022-07-06 15:39 ` Casey Schaufler
2022-07-07 8:54 ` Dmitry Kasatkin
2022-07-06 15:47 ` Igor Zhbanov
2022-07-07 8:54 ` Dmitry Kasatkin
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).