SELinux System Administration
暫譯: SELinux 系統管理

Sven Vermeulen

  • 出版商: Packt Publishing
  • 出版日期: 2013-09-03
  • 售價: $1,600
  • 貴賓價: 9.5$1,520
  • 語言: 英文
  • 頁數: 120
  • 裝訂: Paperback
  • ISBN: 1783283173
  • ISBN-13: 9781783283170
  • 相關分類: Linux
  • 已過版

買這商品的人也買了...

商品描述

With a command of SELinux you can enjoy watertight security on your Linux servers. This guide shows you how through examples taken from real-life situations, giving you a good grounding in all the available features.

Overview

  • Use SELinux to further control network communications
  • Enhance your system's security through SELinux access controls
  • Set up SELinux roles, users and their sensitivity levels

In Detail

NSA Security-Enhanced Linux (SELinux) is a set of patches and added utilities to the Linux kernel to incorporate a strong, flexible, mandatory access control architecture into the major subsystems of the kernel. With its fine-grained yet flexible approach, it is no wonder Linux distributions are firing up SELinux as a default security measure.

SELinux System Administration covers the majority of SELinux features through a mix of real-life scenarios, descriptions, and examples. Everything an administrator needs to further tune SELinux to suit their needs are present in this book.

This book touches on various SELinux topics, guiding you through the configuration of SELinux contexts, definitions, and the assignment of SELinux roles, and finishes up with policy enhancements. All of SELinux's configuration handles, be they conditional policies, constraints, policy types, or audit capabilities, are covered in this book with genuine examples that administrators might come across.

By the end, SELinux System Administration will have taught you how to configure your Linux system to be more secure, powered by a formidable mandatory access control.

What you will learn from this book

  • Enable and disable features selectively or even enforce them to a granular level
  • Interpret SELinux logging to make security-conscious decisions
  • Assign new contexts and sensitivity labels to files and other resources
  • Work with mod_selinux to secure web applications
  • Use tools like sudo, runcon, and newrole to switch roles and run privileged commands in a safe environment
  • Use iptables to assign labels to network packets
  • Configure IPSec and NetLabel to transport SELinux contexts over the wire
  • Build your own SELinux policies using reference policy interfaces

Approach

A step-by-step guide to learn how to set up security on Linux servers by taking SELinux policies into your own hands.

Who this book is written for

Linux administrators will enjoy the various SELinux features that this book covers and the approach used to guide the admin into understanding how SELinux works. The book assumes that you have basic knowledge in Linux administration, especially Linux permission and user management.

商品描述(中文翻譯)

使用 SELinux,您可以在 Linux 伺服器上享受無懈可擊的安全性。本指南通過真實情境中的範例向您展示如何做到這一點,讓您對所有可用功能有良好的基礎認識。

概述
- 使用 SELinux 進一步控制網路通信
- 通過 SELinux 存取控制增強系統安全性
- 設定 SELinux 角色、使用者及其敏感性等級

詳細內容
NSA 安全增強 Linux(SELinux)是一組對 Linux 核心的修補程式和附加工具,旨在將強大、靈活的強制存取控制架構納入核心的主要子系統。由於其細緻而靈活的方法,Linux 發行版將 SELinux 作為預設安全措施也就不足為奇了。

《SELinux 系統管理》通過真實情境、描述和範例涵蓋了大多數 SELinux 功能。本書中包含了管理員需要進一步調整 SELinux 以滿足其需求的所有內容。

本書涉及各種 SELinux 主題,指導您配置 SELinux 上下文、定義及 SELinux 角色的分配,並以政策增強作結。本書涵蓋了所有 SELinux 的配置處理,包括條件政策、約束、政策類型或審計能力,並提供管理員可能遇到的真實範例。

到最後,《SELinux 系統管理》將教會您如何配置您的 Linux 系統以提高安全性,並由強大的強制存取控制提供支持。

您將從本書中學到的內容
- 有選擇性地啟用和禁用功能,甚至強制執行到細粒度的層級
- 解讀 SELinux 日誌以做出安全意識的決策
- 為檔案和其他資源分配新的上下文和敏感性標籤
- 使用 mod_selinux 來保護網路應用程式
- 使用 sudo、runcon 和 newrole 等工具在安全環境中切換角色並執行特權命令
- 使用 iptables 為網路封包分配標籤
- 配置 IPSec 和 NetLabel 以在網路上傳輸 SELinux 上下文
- 使用參考政策介面建立自己的 SELinux 政策

方法
逐步指南,學習如何通過掌握 SELinux 政策來在 Linux 伺服器上設置安全性。

本書的讀者對象
Linux 管理員將會喜歡本書涵蓋的各種 SELinux 功能,以及用於指導管理員理解 SELinux 工作原理的方法。本書假設您具備基本的 Linux 管理知識,特別是 Linux 權限和使用者管理。