LSS: Kernel security subsystem reports
LSS: Kernel security subsystem reports
Posted Sep 28, 2012 12:54 UTC (Fri) by spender (guest, #23067)In reply to: LSS: Kernel security subsystem reports by nix
Parent article: LSS: Kernel security subsystem reports
Off-topic: it's also funny to go back and read arguments in posts like this: https://lwn.net/Articles/181508/
Yes, I am aware of its codomain/subdomain history. I'm not sure if you are or if you merely regurgitated information from the Wikipedia page for AppArmor. I urge you, since this entire discussion is about learning modes, to find any reference to a codomain/subdomain learning mode prior to mine in 2002. I can tell you that you won't find one, as this was the state of subdomain's "learning mode" circa 2005:
http://stuff.mit.edu/afs/athena/system/amd64_deb50/os/usr...
A couple lines of perl operating effectively no differently than audit2allow. This is not real learning. It provides no predictive power and thus will require manual intervention to create working policies. Obviously the learning SELinux is trying to match is that within grsecurity, which is significantly more advanced than audit2allow. It knows when to create roles and subjects, when to generalize file and network accesses on a number of levels, learns resource usage, offers simple human-understandable customization based on simple questions like "what resources are sensitive?" For what it's worth, these completely-automated policies have also held up well under formal analysis: http://secgroup.ext.dsi.unive.it/wp-content/uploads/2012/...
This information is more for the other readers really, as you're a hopeless cause: a glib peddler of intellectual dishonesty, arguing for the sake of semantic argument.
-Brad
