Language Selection

English French German Italian Portuguese Spanish

Overview of Linux Kernel Security Features

Filed under
Linux

In this article, we'll take a high-level look at the security features of the Linux kernel. We'll start with a brief overview of traditional Unix security, and the rationale for extending that for Linux, then we'll discuss the Linux security extensions.

Unix Security – Discretionary Access Control

Linux was initially developed as a clone of the Unix operating system in the early 1990s. As such, it inherits the core Unix security model—a form of Discretionary Access Control (DAC). The security features of the Linux kernel have evolved significantly to meet modern requirements, although Unix DAC remains as the core model.

Briefly, Unix DAC allows the owner of an object (such as a file) to set the security policy for that object—which is why it's called a discretionary scheme. As a user, you can, for example, create a new file in your home directory and decide who else may read or write the file. This policy is implemented as permission bits attached to the file's inode, which may be set by the owner of the file. Permissions for accessing the file, such as read and write, may be set separately for the owner, a specific group, and other (i.e. everyone else). This is a relatively simple form of access control lists (ACLs).

rest here




More in Tux Machines

Samsung Officially Launches their Tizen Curved SUHD 4K TVs in the Philippines

The new line of Tizen 4K Samsung SUHD TVs has now officially been launched in the Philippines at an event held a few days ago. The new line-up of TVs includes the JS9500, JS9000 and JS8500 models, supporting screen sizes ranging from 55 to 88 inches. Samsung boasts that their TV technology, which uses nano-crystal semiconductors, leads in color and brightness compared to its competitors. Read more

Cloudsto X86 Nano PC is a tiny desktop with Ubuntu Linux (or Windows)

The folks at UK retailer Cloudsto have been offering tiny desktop computers loaded with Ubuntu Linux for a little while. But most have basically been Ubuntu versions of existing Android boxes with ARM-based processors. Now Cloudsto is introducing a line of mini PCs with x86 processors, starting with the Cloudsto X86 Nano Mini PC. It’s available with either Windows 8.1 or Ubuntu 14.04. Read more

EMC to open-source ViPR - and lots of other stuff apparently

ViPR is software storage controller tech that separates the control and data planes of operation, enabling different data services to be layered onto a set of storage hardware products - such as EMC's own arrays, Vblocks, selected third-party arrays, JBODs and cloud storage. The data services are typically ways of accessing data, such as file services, The open source software will be called Project CoprHD* and be made available on GitHub for community development. It will include all the storage automation and control functionality and be supplied under the Mozilla Public License 2.0 (MPL 2.0). Public supporting partners for CoprHD are Intel, Verizon and SAP. Read more