Loading...
Please wait, while we are loading the content...
Similar Documents
Integrating selinux with security-typed languages (2007)
| Content Provider | CiteSeerX |
|---|---|
| Author | Hicks, Boniface Rueda, Ra Jaeger, Trent Mcdaniel, Patrick |
| Description | Traditionally, operating systems have enforced MAC and information flow policies with minimal dependence on application programs. However, there are many cases where systems depend on user-level programs to enforce information flows. Previous approaches to handling this problem, such as privilege-separation of application components or assuming trust in application information flow enforcement, are prone to error and cumbersome to manage. On the other hand, recent advances in the area of security-typed languages have enabled the development of realistic applications with formally and automatically verified information flow controls. In this paper, we examine what it takes to integrate information flow enforcement of applications written in a security-typed extension of Java (called Jif) with SELinux. To this end, we have extended the Jif infrastructure to support interaction with SELinux security contexts, and we describe the SELinux policy and system calls which are necessary for a successful integration. We have also identified the need for further services, such as a means of formally verifying compliance between information flow policies. We have demonstrated the utility, flexibility and security of our approach by constructing a prototype multi-level secure email client. |
| File Format | |
| Language | English |
| Publisher Date | 2007-01-01 |
| Publisher Institution | In Proceedings of the 3rd SELinux Symposium |
| Access Restriction | Open |
| Subject Keyword | Minimal Dependence Realistic Application Jif Infrastructure Many Case Selinux Policy Application Program Application Component Security-typed Language Information Flow User-level Program Selinux Security Context Successful Integration System Call Application Information Flow Enforcement Verified Information Flow Control Security-typed Extension Previous Approach Recent Advance Information Flow Policy Information Flow Enforcement Prototype Multi-level Secure Email Client |
| Content Type | Text |
| Resource Type | Article |