loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Fourth IEEE International Workshop on Policies for Distributed Systems and Networks (POLICY'03)
Analyzing Security-Enhanced Linux Policy Specifications
Lake Como, Italy
June 04-June 06
ISBN: 0-7695-1933-4
Myla Archer, Naval Research Laboratory
Elizabeth Leonard, Naval Research Laboratory
Matteo Pradella, Politecnico di Milano
NSA's Security-Enhanced (SE) Linux enhances Linux by providing a specification language for security policies and a Flask-like architecture with a security server for enforcing policies defined in the language. It is natural for users to expect to be able to analyze the properties of a policy from its specification in the policy language. But this language is very low level, making the high level properties of a policy difficult to deduce by inspection. For this reason, tools to help users with the analysis are necessary. The NRL project on analyzing SE Linux policies aims first to use mechanized support to analyze an example policy specification and then to customize this support for use by practitioners in the open source software community. This paper describes how we model policies in the analysis tool TAME, the kinds of analysis we can support, and prototype mechanical support to enable others to model their policies in TAME. The paper concludes with some general observations on desirable properties for a policy language.
Citation:
Myla Archer, Elizabeth Leonard, Matteo Pradella, "Analyzing Security-Enhanced Linux Policy Specifications," policy, pp.158, Fourth IEEE International Workshop on Policies for Distributed Systems and Networks (POLICY'03), 2003
Usage of this product signifies your acceptance of the Terms of Use.