linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* systrace for linux
@ 2002-10-18 19:10 Niels Provos
  2002-10-18 19:49 ` Karim Yaghmour
  0 siblings, 1 reply; 2+ messages in thread
From: Niels Provos @ 2002-10-18 19:10 UTC (permalink / raw)
  To: linux-kernel; +Cc: marius

Hi,

Marius A. Eriksen just finished the Linux port of systrace.  You can
find the kernel patch at

  http://www.citi.umich.edu/u/provos/systrace/linux.html

Systrace is a fine grained sandbox for applications and system services.
It supports interactive policy generation, intrusion detection, policy
enforcement, privilege elevation, etc.  More information at

  http://www.citi.umich.edu/u/provos/systrace/

Comments are appreciated.

Niels.

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: systrace for linux
  2002-10-18 19:10 systrace for linux Niels Provos
@ 2002-10-18 19:49 ` Karim Yaghmour
  0 siblings, 0 replies; 2+ messages in thread
From: Karim Yaghmour @ 2002-10-18 19:49 UTC (permalink / raw)
  To: Niels Provos, LTT-Dev; +Cc: linux-kernel, marius


Hello Niels,

This is the sort of facility which can easily go on top of the existing
LTT infrastructure (http://www.opersys.com/LTT) since most of the events
you need are already cleanly caught by LTT. If we'd reintegrate the
event callback mechanisms we removed on Ingo Molnar's request (albeit
exporting them as GPLonly this time), systrace would then be easily
maintained as a loadable kernel module. In addition, since LTT already
has appropriate hooks for 6 architectures, systrace would immediately
become available on those archs (i386, PPC, S/390, ARM, MIPS, SH).

Karim

Niels Provos wrote:
> Marius A. Eriksen just finished the Linux port of systrace.  You can
> find the kernel patch at
> 
>   http://www.citi.umich.edu/u/provos/systrace/linux.html
> 
> Systrace is a fine grained sandbox for applications and system services.
> It supports interactive policy generation, intrusion detection, policy
> enforcement, privilege elevation, etc.  More information at
> 
>   http://www.citi.umich.edu/u/provos/systrace/
> 
> Comments are appreciated.

===================================================
                 Karim Yaghmour
               karim@opersys.com
      Embedded and Real-Time Linux Expert
===================================================

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2002-10-18 19:37 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2002-10-18 19:10 systrace for linux Niels Provos
2002-10-18 19:49 ` Karim Yaghmour

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).