bk99.de entertain the web since 1997

AppArmor and SELinux compared

Summary

Ralf Spenneberg compares AppArmor and SELinux as mandatory access control systems and shows differences in model, configuration and administration. A less powerful model can be more secure in practice if operators actually maintain it. Additional control only helps if policies match the real behaviour of applications.

Ideas

  • Mandatory access control restricts processes in addition to classic Unix file permissions.
  • AppArmor describes access mainly by file paths.
  • SELinux labels objects and subjects with security contexts.
  • Both systems reduce damage after an application has been compromised.

Recommendations

  • Get to know denials in logging mode first.
  • Extend policies in a targeted way and avoid blanket permissions.

References

Watch the talk

Search the Web Archive