Re: New HIPS based on SELinux

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello,

I think you are misusing the term "HIPS" here, (or using your own definition actually)

Sorry to be pedantic but, SELinux as you know is an add-on (platform
) to the kernel providing Access Control (RBAC, IBAC, MAC and etc.) and MLS (Multi-Level Security)

While encouraging you for your work but I'm afraid it is as you explained yourself:

" User Data Defence includes set of template policies, which makes process of creation SELinux specifications for user mode applications simple .... "

in other words, It is A Graphical user Interface for creating SELinux Policies


BUT, Host based Intrusion Prevention System,  (HIPS)

or more accurately Host Based Intrusion Detection and Prevention System (HIDPS) requires a method to detect attacks and react upon them or interact with them (Preemptive approach), taking into account the server or workstation parameters and conditions, utilizing either or combination of :

1) Signature based analysis of threats


2) Anomaly based analysis of threats against the server,
in example statistical analysis, Integrity analysis and etc.


3) Protocol Anomaly Analysis


4) Heuristic analysis
combination of methods using Expert systems or other means in Artificial Intelligence/Synthetic Intelligence such as Petri nets, Artificial Neural Networks and etc.


Best Regards,

Patrick K.


On 10/5/2011 2:30 PM, Hramchenko wrote:
Hi all.

I have created new host intrusion prevention system based on SELinux.
It's focused on protection user's data.
One of the main goals was to create lightweight replacement of
setroubleshootd.

I hope my program will be useful for SELinux users.

The project home page:
https://github.com/Hramchenko/userdatadefence/

With respect, Hramchenko Vitaliy.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.


[Index of Archives]     [Selinux Refpolicy]     [Linux SGX]     [Fedora Users]     [Fedora Desktop]     [Yosemite Photos]     [Yosemite Camping]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux