Digest of Overview of Linux Kernel Security Features

Linux kernel Security:

I. DAC: Discretionary Access Control, the core security model of UNIX.

II. POSIX ACL: Extended DAC

III. Namespaces

     Derived from Plan 9.

     Process has its own view of resources, for example filesystem.

IV. Network Security: Netfilters

     1. iptables: network layer

     2. ebtables: link layer and linux bridge

     3. arptables: for arp protocol

     4. IPsec: network layer

V. Cryptography

    1. Cryptographic API, such as IPsec

    2. Disk encryption, such as ecryptfs and dm-crypt

    3. kernel module signature

VI. LSM: Linux Security Modules

    1. MAC: Mandatory Access Control

        i. SELinux: Security Enhanced Linux

        ii. Smack: Simplified MAC Kernel?

        iii. AppArmor: Used by Ubuntu and OpenSUSE

        iv. TOMOYO: path-based security

        v. Yama

VII. Audit

VIII. Seccomp: Secure computing

IX. Integrity management

X. Hardening and Platform Security

    for example: ASLR--Address Space Layout Randomization

 

 This is a guest post from James Morris, the Linux kernel security subsystem maintainer and manager of the mainline Linux kernel development team at Oracle.

URL: https://www.linux.com/learn/overview-linux-kernel-security-features

 

转载于:https://www.cnblogs.com/clblacksmith/p/9254040.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值