JOURNAL ARTICLE

Analyzing security-enhanced Linux policy specifications

Abstract

NSA's security-enhanced (SE) Linux enhances Linux by providing a specification language for security policies and a flask-like architecture with a security server for enforcing policies defined in the language. It is natural for users to expect to be able to analyze the properties of a policy from its specification in the policy language. But this language is very low level, making the high level properties of a policy difficult to deduce by inspection. For this reason, tools to help users with the analysis are necessary. The NRL project on analyzing SE Linux policies aims first to use mechanized support to analyze an example policy specification and then to customize this support for use by practitioners in the open source software community. We describe the model policies in the analysis tool TAME, the kinds of analysis we can support, and prototype mechanical support to enable others to model their policies in TAME. We conclude with some general observations on desirable properties for a policy language.

Keywords:
Computer science Security policy Software Architecture Specification language Operating system Computer security Software engineering

Metrics

16
Cited By
1.93
FWCI (Field Weighted Citation Impact)
21
Refs
0.89
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Security and Verification in Computing
Physical Sciences →  Computer Science →  Artificial Intelligence
Access Control and Trust
Social Sciences →  Social Sciences →  Sociology and Political Science
Advanced Malware Detection Techniques
Physical Sciences →  Computer Science →  Signal Processing

Related Documents

JOURNAL ARTICLE

A Security Policy Configuration for the Security-Enhanced Linux

Stephen Smalley

Year: 2002 Vol: 33 (1)Pages: 60-65
JOURNAL ARTICLE

Security Enhanced Linux

Kunz, Oliver

Journal:   Zenodo (CERN European Organization for Nuclear Research) Year: 2014
JOURNAL ARTICLE

Security Enhanced Linux

Kunz, Oliver

Journal:   Zenodo (CERN European Organization for Nuclear Research) Year: 2014
BOOK-CHAPTER

Information Flow Query and Verification for Security Policy of Security-Enhanced Linux

Yiming ChenYung‐Wei Kao

Lecture notes in computer science Year: 2006 Pages: 389-404
© 2026 ScienceGate Book Chapters — All rights reserved.