SELinux System Administration - Third Edition: Implement mandatory access control to secure applications, users, and information flows on Linux
暫譯: SELinux 系統管理 - 第三版:在 Linux 上實施強制存取控制以保護應用程式、使用者和資訊流
Vermeulen, Sven
- 出版商: Packt Publishing
- 出版日期: 2020-12-04
- 售價: $2,220
- 貴賓價: 9.5 折 $2,109
- 語言: 英文
- 頁數: 458
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1800201478
- ISBN-13: 9781800201477
-
相關分類:
Linux
海外代購書籍(需單獨結帳)
商品描述
Enhance Linux security, application platforms, and virtualization solutions with SELinux to work within your boundaries, your rules, and your policies
Key Features
- Learn what SELinux is, and how it acts as a mandatory access control system on Linux
- Apply and tune SELinux enforcement to users, applications, platforms, and virtualization solutions
- Use real-life examples and custom policies to strengthen the security posture of your systems
Book Description
Linux is a dominant player in many organizations and in the cloud. Securing the Linux environment is extremely important for any organization, and Security-Enhanced Linux (SELinux) acts as an additional layer to Linux system security.
SELinux System Administration covers basic SELinux concepts and shows you how to enhance Linux system protection measures. You will get to grips with SELinux and understand how it is integrated. As you progress, you'll get hands-on experience of tuning and configuring SELinux and integrating it into day-to-day administration tasks such as user management, network management, and application maintenance. Platforms such as Kubernetes, system services like systemd, and virtualization solutions like libvirt and Xen, all of which offer SELinux-specific controls, will be explained effectively so that you understand how to apply and configure SELinux within these applications. If applications do not exert the expected behavior, you'll learn how to fine-tune policies to securely host these applications. In case no policies exist, the book will guide you through developing custom policies on your own.
By the end of this Linux book, you'll be able to harden any Linux system using SELinux to suit your needs and fine-tune existing policies and develop custom ones to protect any app and service running on your Linux systems.
What You Will Learn
- Understand what SELinux is and how it is integrated into Linux
- Tune Linux security using policies and their configurable settings
- Manage Linux users with least-privilege roles and access controls
- Use SELinux controls in system services and virtualization solutions
- Analyze SELinux behavior through log events and policy analysis tools
- Protect systems against unexpected and malicious behavior
- Enhance existing policies or develop custom ones
Who this book is for
This Linux sysadmin book is for Linux administrators who want to control the secure state of their systems using SELinux, and for security professionals who have experience in maintaining a Linux system and want to know about SELinux. Experience in maintaining Linux systems, covering user management, software installation and maintenance, Linux security controls, and network configuration is required to get the most out of this book.
商品描述(中文翻譯)
透過 SELinux 增強 Linux 安全性、應用平台和虛擬化解決方案,以符合您的邊界、規則和政策
主要特點
- 了解 SELinux 是什麼,以及它如何作為 Linux 上的強制存取控制系統
- 將 SELinux 強制執行應用於用戶、應用程式、平台和虛擬化解決方案並進行調整
- 使用實際案例和自定義政策來加強系統的安全性
書籍描述
Linux 在許多組織和雲端中佔據主導地位。確保 Linux 環境的安全對任何組織來說都是極其重要的,而安全增強 Linux(SELinux)則作為 Linux 系統安全的額外層級。
《SELinux 系統管理》涵蓋基本的 SELinux 概念,並展示如何增強 Linux 系統的保護措施。您將掌握 SELinux,並了解它是如何整合的。隨著進展,您將獲得調整和配置 SELinux 的實踐經驗,並將其整合到日常管理任務中,例如用戶管理、網路管理和應用維護。像 Kubernetes 這樣的平台、systemd 這樣的系統服務,以及 libvirt 和 Xen 這樣的虛擬化解決方案,這些都提供 SELinux 特定的控制,將有效地解釋,以便您了解如何在這些應用中應用和配置 SELinux。如果應用程式未能表現出預期的行為,您將學習如何微調政策以安全地托管這些應用。如果沒有現成的政策,這本書將指導您自行開發自定義政策。
在這本 Linux 書籍結束時,您將能夠使用 SELinux 加固任何 Linux 系統,以滿足您的需求,並微調現有政策或開發自定義政策,以保護在您的 Linux 系統上運行的任何應用和服務。
您將學到什麼
- 了解 SELinux 是什麼以及它如何整合到 Linux 中
- 使用政策及其可配置設置調整 Linux 安全性
- 以最小權限角色和存取控制管理 Linux 用戶
- 在系統服務和虛擬化解決方案中使用 SELinux 控制
- 通過日誌事件和政策分析工具分析 SELinux 行為
- 保護系統免受意外和惡意行為的影響
- 增強現有政策或開發自定義政策
本書適合誰
這本 Linux 系統管理書籍適合希望使用 SELinux 控制其系統安全狀態的 Linux 管理員,以及有維護 Linux 系統經驗並希望了解 SELinux 的安全專業人士。需要具備維護 Linux 系統的經驗,包括用戶管理、軟體安裝和維護、Linux 安全控制和網路配置,以便充分利用本書。