Check out the new USENIX Web site. next up previous
Next: Analysis Implementation Up: Analyzing Integrity Protection in Previous: Manual Analysis


Integrity Analysis


Figure 4: Gokyo graphical policy model implementation of integrity.

In this section, we use Gokyo to analyze our proposed TCB to identify the integrity conflicts, classify according to best possible resolution, and choose the likely resolution. The likely resolution is chosen based on manual analysis of the conflict. The key results are the resultant TCB (i.e., does it need to be expanded and how?) and proposed SELinux policy changes needed to achieve this TCB. Detailed discussion of the Gokyo tool itself is provided elsewhere [13].





Trent Jaeger
2003-05-11