2008 IEEE Workshop on Policies for Distributed Systems and Networks
Systematic Policy Analysis for High-Assurance Services in SELinux
June 02-June 04
ISBN: 978-0-7695-3133-5
Identifying and protecting the trusted computing base (TCB) of a system is an important task to provide high- assurance services since a set of trusted subjects should be legitimately articulated for target applications. In this pa- per, we present a formal policy analysis framework to iden- tify TCB with the consideration of specific security goals. We also attempt to model information flows between do- mains in SELinux policies and detect security violations among information flows using Colored Petri Nets.
Index Terms:
Policy Analysis, SELinux
Citation:
Gail-Joon Ahn, Wenjuan Xu, Xinwen Zhang, "Systematic Policy Analysis for High-Assurance Services in SELinux," policy, pp.3-10, 2008 IEEE Workshop on Policies for Distributed Systems and Networks, 2008