Sai Varshith H O, Vaidya Jaideep, Sural Shamik, Atluri Vijayalakshmi
Indian Institute of Technology Kharagpur, India.
Rutgers University, USA.
Asia CCS 22 (2022). 2022 May;2022:1237-1239. doi: 10.1145/3488932.3527293. Epub 2022 May 30.
Linux has built-in security features based on discretionary access control that can be enhanced using the Linux Security Module (LSM) framework. However, so far there has been no reported work on strengthening Linux with Attribute-Based Access Control (ABAC), which is gaining in popularity in recent years due to its flexibility and dynamic nature. In this paper, a method for enabling ABAC for Linux file system objects using LSM is proposed. We report initial experimental results and also share our public repository links for integrating ABAC in any Linux installation.
Linux具有基于自主访问控制的内置安全功能,可使用Linux安全模块(LSM)框架进行增强。然而,到目前为止,尚未有关于使用基于属性的访问控制(ABAC)强化Linux的报道,由于其灵活性和动态特性,ABAC近年来越来越受欢迎。本文提出了一种使用LSM为Linux文件系统对象启用ABAC的方法。我们报告了初步的实验结果,并分享了在任何Linux安装中集成ABAC的公共存储库链接。