Top Banner
Security Enhanced Linux Control de acceso obligatorio Alex Eguia Sánchez Ander Suárez Martínez Jon Ander Peñalba Esteban
19

Vision general de SELinux

Jul 04, 2015

Download

Technology

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Vision general de SELinux

Security Enhanced Linux

Control de acceso obligatorio

Alex Eguia SánchezAnder Suárez MartínezJon Ander Peñalba Esteban

Page 2: Vision general de SELinux

CONTROL DE ACCESO

Page 3: Vision general de SELinux

CONTROL DE ACCESO DISCRECIONAL

Page 4: Vision general de SELinux
Page 5: Vision general de SELinux

NAVEGADORES

Page 6: Vision general de SELinux
Page 7: Vision general de SELinux
Page 8: Vision general de SELinux
Page 9: Vision general de SELinux
Page 10: Vision general de SELinux

Security Enhanced Linux

Page 11: Vision general de SELinux

SEGURIDAD A NIVEL DE KERNEL

Page 12: Vision general de SELinux
Page 13: Vision general de SELinux

ControlAccesoObligatorio

Page 14: Vision general de SELinux

Reglas

Page 15: Vision general de SELinux

allow icecast_t self:fifo_file rw_fifo_file_perms;allow icecast_t self:unix_stream_socket create_stream_socket_perms;files_read_etc_files(icecast_t)manage_dirs_pattern(icecast_t, icecast_var_run_t,  icecast_var_run_t)

Un conjuro...

Page 16: Vision general de SELinux
Page 17: Vision general de SELinux

Política de referencia SELinux

Page 18: Vision general de SELinux

NuevasAplicaciones

Page 19: Vision general de SELinux

Veamos un ejemplo...