Walsh: Introducing the SELinux Sandbox
Walsh: Introducing the SELinux Sandbox
Posted May 27, 2009 3:13 UTC (Wed) by spender (guest, #23067)In reply to: Walsh: Introducing the SELinux Sandbox by gdt
Parent article: Walsh: Introducing the SELinux Sandbox
http://invisiblethingslab.com/pub/xenfb-adventures-10.pdf
http://marc.info/?l=dailydave&m=117294179528847&w=2
http://kernelbof.blogspot.com/
http://www.immunityinc.com/documentation/cloudburst-vista...
http://www.usenix.org/event/hotos09/tech/full_papers/arno...
I'm assuming the "no actual compromise [...] has succeeded" part of the above comment was a typo. Given that "an attacker seeking to exploit unidentified vulnerabilities in Linux bug-fix disclosures would have [...] between 4 and 16 bugs with hidden impact waiting for him or her at any time in the last three years", it might be a good idea to put some focus on improving the security of the kernel itself, upon which the integrity of these "privacy and integrity" protectors depends.
-Brad
