Presentation is loading. Please wait.

Presentation is loading. Please wait.

Mandatory Access Control and the Real World

Similar presentations


Presentation on theme: "Mandatory Access Control and the Real World"— Presentation transcript:

1 Prolog to Lecture 3 CS 236 On-Line MS Program Networks and Systems Security Peter Reiher

2 Mandatory Access Control and the Real World
For a long time, things like Bell-La Padula were hard to run Real-world commercial systems did not support them That’s changing

3 SE Linux and Flask Security Enhanced Linux
Developed by NSA researchers Open source, like all Linux Implementation of the Flask security architecture Which allows flexible use of mandatory access control

4 What Can You Do With Flask?
Multi-level security Including Bell La Padula Domain Type Enforcement Role-based Access Control Many other types of mandatory access control policies No superuser, many other common Linux/Unix security problems avoided

5 Flask and Solaris Flask architecture to be added to Oracle Solaris operating system Essentially the same architecture as in SE Linux

6 What Does This Mean For You?
You can get usable, commercial operating systems with MAC Even operating systems with strong industry support Well, so what?

7 Is MAC For You? MAC is only useful where it makes sense to force policy to be followed Typically not on a single user’s personal machine More common on industry installations Especially those with military connections Do you need to guarantee access control properties? Regardless of how foolish your users are?


Download ppt "Mandatory Access Control and the Real World"

Similar presentations


Ads by Google