documentation:rsbac_handbook:configuration_basics:identify_requirements:system_base
=>  Releases

Current version
Git/Latestdiff: 1.5.6

Latest Snapshots
Produced after each commit or rebase to new upstream version

GIT clone e.g. at git://git.rsbac.org/linux-6.18.y

GIT Web at GitHub and Launchpad

=>  Events

No events planned

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
documentation:rsbac_handbook:configuration_basics:identify_requirements:system_base [2006/05/17 12:50] – created aodocumentation:rsbac_handbook:configuration_basics:identify_requirements:system_base [Unknown date] (current) – removed - external edit (Unknown date) 127.0.0.1
Line 1: Line 1:
-===== System Base Protection ===== 
-The following categories of objects usually have to be controlled: 
- 
-  * **Filesystem Structure:** Some important directories must exist on a functional system, e.g. /bin or /etc. Removing or replacing them can lead to denial of service or illegal accesses. 
-  * **Executables:** Program files are liable to replacement or infection by trojans or viruses, and deletion can lead to denial of service. 
-  * **Dynamic Libraries:** Like program files, libraries contain executable code and thus can be infected. Also, many programs may depend on a single library, making its infection specially dangerous. 
-  * **Configuration Files:** Many programs are influenced by configuration files, which thus have to be protected to avoid unwanted program behaviour. 
-  * **Kernel Objects:** All kernel code, like kernel images and loadable modules, is stored in files on disk. Modification of these files can provide uncontrollable access to the whole system. Additionally, standard Linux kernels give the system administrator raw access to kernel memory through devices and special files. This can be used to bypass the official kernel entry points. 
-  * **Devices:** Direct access to some devices, like disk partitions, bypasses individual object access control and thus must be prevented. Some devices also provide extra functionality, which is not available otherwise. 
-  * **Authentication Data:** The data used for authentication are critical for access control. They must be protected from all accesses which are not strictly necessary. 
-  * **Network Resources:** Remote servers as well as local network sockets provide essential services to many users. Restricted network access protects network services from being attacked by local users or compromised services. 
-  * **Other Objects:** Some additional objects should be taken into account, like log data, boot loaders, hardware ports, etc. The actual selection depends on the system configuration. 
  
//
documentation/rsbac_handbook/configuration_basics/identify_requirements/system_base.1147870254.txt.gz · Last modified: 2006/05/19 14:51 (external edit)

documentation/rsbac_handbook/configuration_basics/identify_requirements/system_base.1147870254.txt.gz · Last modified: 2006/05/19 14:51 (external edit)
This website is kindly hosted by m-privacy