Access decisions Access vector >A bitmap associated with each object class File security dass aea) ainqune ap A simplified access vector for the file class Science and Technol 嵌入式系统实验室 EMBEDDED SYSTEM LABORATORY SUZHOU INSTITUTE FON ADVANCED STUDY OF USTC
Access decisions ❖Access vector ➢A bitmap associated with each object class A simplified access vector for the file class
Make the access decision by considering >主体的安全上下文 File security dass >客体的安全上下文 ainex 道 墨 >客体的安全类型 >Action 19 Allow 必返回:访问向量 Auditallow 3个向量中,允许主体 Dontaudit Append/create客体 A simplified access vector resulting from an access decision MI Science and Technole 嵌入式系统实验室 EMBEDDED SYSTEM LABORATORY SUZHOU INSTITUTE FON ADVANCED STUDY OF USTC
❖Make the access decision by considering ➢主体的安全上下文 ➢客体的安全上下文 ➢客体的安全类型 ➢Action ❖返回:访问向量 3个向量中,允许主体 Append/create客体 A simplified access vector resulting from an access decision
00550: /米米 00551: 米 security_compute_av-Compute access vector decisions. 00552: 米 @ssid:source security identifier 00553: 米( @tsid:target security identifier 00554: 米 @tclass:target security class 00555: @requested:requested permissions 00556: @avd:access vector decisions 00557: 米 00558: Compute a set of access vector decisions based on the 00559: 米 SID pair (@ssid,@tsid)for the permissions in @tclass. 00560: Return -%EINVAL if any of the parameters are invalid or %0 00561: if the access vector decisions were computed successfully. 00562: */ 00563: int security compute_av(u32 ssid 00564: u32 tsid, 00565: u16 tclass 00566: u32 requested, 00567: struct av decision *avd) 00568: cience and Techn 嵌入式系统实验室 EMBEDDED SYSTEM LABORATORY SUZHOU INSTITUTE FON ADVANCED STUDY OF USTC
Transition decisions For newly created objects >Process(subject)creation >File (object)creation 1958 、论Th 嵌入式系统实验室 EMBEDDED SYSTEM LABORATORY SUZHOU INSTITUTE FON ADVANCED STUDY OF USTC
Transition decisions ❖For newly created objects ➢Process (subject) creation ➢File (object) creation
主要内容 *Definition History Concepts 空大 *Architecture SELinux Policy Language Userspace 冬实现 使用 of science and Technolooyot china 嵌入式系统实验室 EMBEDDED SYSTEM LABORATORY SUZHOU INSTITUTE FON ADVANCED STUDY OF USTC
主要内容 ❖Definition ❖History ❖Concepts ❖Architecture ❖SELinux Policy Language ❖Userspace ❖实现 ❖使用