About Us Our Work Employment News & Events
MITRE Remote Access for MITRE Staff and Partners Site Map
Our Work

Follow Us:

Visit MITRE on Facebook
Visit MITRE on Twitter
Visit MITRE on Linkedin
Visit MITRE on YouTube
View MITRE's RSS Feeds
View MITRE's Mobile Apps
Home > Our Work > Technical Papers >

Guided Policy Generation for Application Authors

February 2006

Brian T. Sniffen, The MITRE Corporation
David R. Harris, The MITRE Corporation
John D. Ramsdell, The MITRE Corporation

ABSTRACT

Polgen is a tool for human-guided semi-automated SE Linux security policy generation. Polgen processes traces of the dynamic behavior of a target program. In that behavior, it observes instances of information flow patterns such as Pipeline, Interpreter, and Proxy. Based on the patterns it detects, Polgen creates new SE Linux types and generates policy rules. Because the dynamic behavior is insufficient to determine security policy, Polgen presents a wizard-style interface for human interaction. We call the interaction "guided automatic policy generation." We designed Polgen primarily for security administrators who confront unfamiliar programs and are obliged to integrate them into existing policy. This paper highlights changes made to Polgen to adapt it to the needs of application authors, people that are less likely to be well versed in SE Linux policy than are security administrators. Key changes include an architecture specification language and a refinement of the wizard-style interface for application authors. When complete, this tool will expand the community of policy authors, and further accelerate the adoption of SE Linux.

View/Download Document

Additional Search Keywords

N/A

 

Page last updated: March 22, 2006   |   Top of page

Homeland Security Center Center for Enterprise Modernization Command, Control, Communications and Intelligence Center Center for Advanced Aviation System Development

 
 
 

Solutions That Make a Difference.®
Copyright © 1997-2013, The MITRE Corporation. All rights reserved.
MITRE is a registered trademark of The MITRE Corporation.
Material on this site may be copied and distributed with permission only.

IDG's Computerworld Names MITRE a "Best Place to Work in IT" for Eighth Straight Year The Boston Globe Ranks MITRE Number 6 Top Place to Work Fast Company Names MITRE One of the "World's 50 Most Innovative Companies"
 

Privacy Policy | Contact Us