AppArmor and SELinux compared
Summary
Ralf Spenneberg compares AppArmor and SELinux as mandatory access control systems and shows differences in model, configuration and administration. A less powerful model can be more secure in practice if operators actually maintain it. Additional control only helps if policies match the real behaviour of applications.
Ideas
- Mandatory access control restricts processes in addition to classic Unix file permissions.
- AppArmor describes access mainly by file paths.
- SELinux labels objects and subjects with security contexts.
- Both systems reduce damage after an application has been compromised.
Recommendations
- Get to know denials in logging mode first.
- Extend policies in a targeted way and avoid blanket permissions.
References
Links to the original source and the Web Archive open in a new tab.