next up previous contents
Next: LD_PRELOAD Attack Up: LinSec Capability Model Previous: INET Socket Capability-Based Protection   Contents


New Capabilities Introduced

Several other capabilities had to be introduced in addition to the existing POSIX and Linux specific capabilities to enable correct functioning of LinSec:



Footnotes

... tools4.7
To perform LinSec administrative tasks, a process needs to have CAP_LINSEC_ADMIN capability in its effective capability set. As static allocation of the capability to any program is regarded risky (due to eg. buffer overflow attacks on the capability model itself), the process is allowed to modify its capability sets, after the user that invoked it has provided correct administrative password.

next up previous contents
Next: LD_PRELOAD Attack Up: LinSec Capability Model Previous: INET Socket Capability-Based Protection   Contents