Research and Implementation on Process Access Control Based on SELinux Mandatory Access Control

Tao ZHANG,Yong ZHANG,Ge NING,Zhong CHEN
DOI: https://doi.org/10.3969/j.issn.1671-1122.2015.12.006
2015-01-01
Abstract:In face of the problem that the vulnerabilities of the common service or process in the Linux system are used to cause the system control to be easily lost, the paper proposes a process access control based on SELinux mandatory access control (PBACS), which can do fine-grained access control for files, processes and services, and can effectively mitigate security threats that caused by the vulnerabilities of system services, thus makes the server system more secure. The paper gives functional test and performance test on PBACS. Test result shows that PBACS meets design requirements, and can provide lower access control granularity in system process level. PBACS can be widely applied to reinforce Linux server system.
What problem does this paper attempt to address?