books:
•
SELinux: NSA's Open Source Security Enhanced Linux
Bill McCarty
O'Reilly Media, Inc.
, 2004 - 254 pages
average customer review:
based on 9 reviews
view larger image
for more information click here
highly recommended
Good Introduction but lacks advanced, how-to information.
Personally, I prefer books to focus either concepts or detailed implementation instructions not both. For complex topics like SE
Linux
, you typically cannot fit the conceptual and pragmatic within one book. McCarty's
SELINUX
is no exception. SELINUX provides an excellent overview of concepts but struggles with policy implementation methods and procedures. I suspect the topic is simply too large for one volume. What implementation advice presented is clear and concise but you will have to search elsewhere for more detailed deployment advice.
Despite these issues, this book is recommended reading for anyone considering implementing SELinux. The conceptual overview is some of the best I've seen since SELinux got its start. Using charts, diagrams and examples, McCarty presents an excellent overview of the nuts and bolts of SELinux. Understanding the principles of Role-Based Access Control, Type Enforcement, and
Security Objects
is critical to both using SELinux and justifying its use. The latter may be a bigger hurdle than many anticipate. The chapters on these areas will arm you with sufficient understanding to make a clear case of why SELinux can and should be implemented in many Linux-based computing environments.
While there are brief examples throughout, the book's third chapter on SELinux installation presents a well-documented, step-by-step guide to installing SELinux. If you've never installed SELinux, these sections will prove very valuable. With clearly numbered steps and command line examples, you can have SELinux installed and configured with a default policy within an hour.
As a mix between the pragmatic and conceptual, SELINUX is a good start on this topic. Entry level SELinux users will probably not learn too much from this book, but if your are looking for a introduction to SELinux concepts along with some pragmatic advice for getting started, then this book may be for you.
for more information click here
Quite short
Really only skimming over the problem, could be more in depth, since most online documentation about SE
Linux
is really skimming over the subject too, or just overly dated.
for more information click here
vastly improved implementation
Se
linux
is a conscious attempt to fundamentally rework and improve linux
security
. Previously, or more to the point, in most current linux machines, the security was somewhat of an ad hoc approach. This is mitigated by a formidable array of
open
source
IDS tools like Ethereal and Snort that let a sysadmin often successfully depend her network and machines.
But as the frequency and virulence of malware attacks has increased, the
Selinux
of this book may be a timely reinforcing of the operating system. As McCarty explains, this book is geared towards a sysadmin, as opposed to a programmer. It discusses the new things you should know. Especially the concepts of role based access model and of domains. The former has shades of DEC's VMS, which had a very mature implementation. Or those of you with mainframe experience may also recognise familiar ideas.
Programmers may find the book a little sparse, as mentioned above. But possibly McCarty is devising a sequel for them.
for more information click here
One of the best on creating a secure Linux system
So what makes Se
linux more
secure than standard Linux? Primarily it is the implementation of role-based access control, sandboxing, and an audit facility that allows the system to log any attempts to exceed specified permissions. It does all this without conflicting with the normal permissions of Linux. If you are able to access a file through normal discretionary access control then the role-based mandatory access control provides additional
security
to determine if you can run the file or not. The only way to
open
a file is if both systems agree that you should be able to open it.
The author covers installation, configuration, administering, and setting up a security policy. The presentation of
SeLinux
is straightforward and the security model is presented in a writing style that makes it clear and understandable to the reader.
SeLinux:
NSA's Open
Source Security
Enhanced Linux
is highly recommended as both a Linux security solution and an excellent book on how to utilize all the resources of SeLinux.
for more information click here
Great Overview to a Potentially Complex Topic
This book is a great introduction to the topic of SE
Linux because
of the information on its developmental background and lucid description of the objectives, advantages and maintenance of a
SELinux system
. I would recommend this book to someone who has a firm grasp of basic
security concepts
and programming principles and is interested in getting exposure to the security
enhanced model
of Linux.
reviews
:
page 1
,
2
The intensive search for a more secure operating system has often left everyday, production computers far behind their experimental, research cousins. Now SE
Linux
(
Security
Enhanced Linux
) dramatically changes this. This best-known and most respected security-related extension to Linux embodies the key advances of the security field. Better yet,
SELinux
is available in widespread and popular distributions of the Linux operating system--including for Debian, Fedora, Gentoo, Red Hat Enterprise Linux, and SUSE--all of it free and
open
source
. SELinux emerged from research by the National Security Agency and implements classic strong-security measures such as role-based access controls, mandatory access controls, and fine-grained transitions and privilege escalation following the principle of least privilege. It compe
nsa
tes for the inevitable buffer overflows and other weaknesses in applications by isolating them and preventing flaws in one application from spreading to others. The scenarios that cause the most cyber-damage these days--when someone gets a toe-hold on a computer through a vulnerability in a local networked application, such as a Web server, and parlays that toe-hold into pervasive control over the computer system--are prevented on a properly administered SELinux system. The key, of course, lies in the words "properly administered." A system administrator for SELinux needs a wide range of knowledge, such as the principles behind the system, how to assign different privileges to different groups of users, how to change policies to accommodate new software, and how to log and track what is going on. And this is where SELinux is invaluable. Author Bill McCarty, a security consultant who has briefed numerous government agencies, incorporates his intensive research into SELinux into this small but information-packed book. Topics include: A readable and concrete explanation of SELinux concepts and the SELinux security model Installation instructions for numerous distributions Basic system and user administration A detailed dissection of the SELinux policy language Examples and guidelines for altering and adding policies With SELinux, a high-security computer is within reach of any system administrator. If you want an effective means of securing your Linux system--and who doesn't?--this book provides the means.
for more information click here
hot
or
not?
What's your opinion?
Write a review and share your thoughts!
recommendations
My favorite Computer Security and Penetration Testing Books
Best Books in Linux and RHCE Certification
enhanced
A Duck in New York City
Online Bookselling: A Practical Guide with Detailed Explanations and ...
Jala
Orthopedic Physical Assessment Enhanced Edition
Off-Ramps and On-Ramps: Keeping Talented Women on the Road to Success ...
security
Computer Security: Art and Science
Security+ Guide to Networking Security Fundamentals, Second Edition
Security in Computing, 4th Edition
Introduction to Security, Eighth Edition
Network Security: Private Communication in a Public World (2nd ...
source
One Minute to Midnight: Kennedy, Khrushchev, and Castro on the Brink ...
The Demon-Haunted World: Science as a Candle in the Dark
The New Glucose Revolution Shopper's Guide to GI Values 2008: The ...
A Fine Balance (Oprah's Book Club)
Retailing Management
search for books
nsa's open
,
enhanced
,
linux
,
nsa
,
open
,
security
,
selinux
,
source
Impressum / about us
books:
other categories
apparel
baby
beauty
books
camera & photo
cell phones
classical music
computers
dvd
software
kitchen
gourmet food
health & personal care
magazines
musical instruments
office products
outdoor living
pc & video games
popular music
electronics
sporting goods
tools & hardware
toys & games
pet supplies
vhs video
watches & jewelry
german
Bücher
DVD
klassische Musik