Capable
Capable
批准号:
10077971
负责人:
金额:
$4.08万
依托单位:
依托单位国家:
英国
项目类别:
Collaborative R&D
财政年份:
2023
资助国家:
英国
项目状态:
已结题
起止时间:
2023 至 --
关键词:
中文摘要
Linux是关键系统(互联网服务和关键基础设施)的主要操作系统。Linux也成为了军方的首选操作系统。在军队中,Linux可能用于保存不同安全级别的数据。它还可以部署在需要一定级别的系统锁定和安全限制的各种场景中。由于操作系统的不同发行版,实现这一点确实具有挑战性。因此,加强Linux的一种方法是在非常低的级别上配置安全性。Linux功能是一种主要的安全控制,它控制进程和应用程序如何与内核交互。所有发行版都使用功能,如果配置正确,它们可能会提供一种有效的方式来统一所有Linux系统的安全配置。一个挑战是功能往往很复杂,需要大量的经验来配置。因此,我们提出了Capable:通过配置系统功能来满足安全需求,从而加强Linux内核。Capable将消除复杂性,并使授权的最终用户能够指定系统锁定级别。Capable将是市场上第一个通过强化内核来保护Linux的解决方案,并满足各种安全认证的安全要求。
英文摘要
Linux is the predominant OS for key systems (Internet Services and critical infrastructure). Linux has also became the preferred OS for the military. Within the military, Linux might be used to hold data for different security classifications. It may also be deployed in various scenarios that demand certain levels of system lock-down and security restrictions. Achieving this is really challenging due to the variant distributions of the OS. Therefore, one way to harden Linux is to configure security at a very low-level. Linux capabilities are one main security control that governs how processes and applications interact with the Kernel. Capabilities are used across all distributions and when configured correctly, they could potentially provide an effective manner to unify security configurations for all Linux systems.One challenge is that capabilities tend to be complicated and require significant experience to configure. Therefore, we propose Capable: that will harden Linux kernels by configuring the system capabilities to meet the security requirements. Capable will remove the complexity and enable authorised end-users to specify the level of system lockdown. Capable will be the first solution in the market to secure Linux through hardening the kernel and to meet the security requirements for various security certifications.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金