Mandatory Access Control
When examining a 0-day exploit you compare:
system directory vs. user home directory vs. root compromise
everything is denied by default.
Mandatory Access Control (MAC)
The SELinux Linux Security Model (LSM) is incorporated in RHEL Core 5 andTrusted X Windows rocks on servicing MAC (as opposed to discretionary access control) with Flask security architecture which essentially breaks down the power of root.
Digg it | Save to del.icio.us | Netscape | Reddit | Stumble It!
- - - - - S P O N S O R I N G A D V E R T I S M E N T - - - - -