请输入您要查询的百科知识:

 

词条 Tomoyo Linux
释义

  1. Overview

  2. Features

  3. History and versions

  4. References

  5. External links

{{more citations needed|date=September 2010}}{{Infobox software
| name = Tomoyo Linux
| logo = TOMOYOLinux penguin.png
| author = NTT Data Corporation
| operating system = Linux
| genre = Mandatory access control
| license = GPL v2
| website = {{url|http://tomoyo.osdn.jp/}}
}}

Tomoyo Linux (stylised as TOMOYO Linux) is a Linux kernel security module which implements mandatory access control (MAC).

Overview

Tomoyo Linux is a MAC implementation for Linux that can be used to increase the security of a system, while also being useful purely as a systems analysis tool. It was launched in March 2003 and was sponsored by NTT Data Corporation until March 2012.[1]

Tomoyo Linux focuses on system behaviour. Tomoyo Linux allows each process to declare behaviours and resources needed to achieve their purpose. When protection is enabled, Tomoyo Linux restricts each process to the behaviours and resources allowed by the administrator.

Features

The main features of Tomoyo Linux include:

  • System analysis
  • Increased security through Mandatory Access Control
  • Automatic policy generation
  • Simple syntax
  • Ease of use

History and versions

Tomoyo was merged in Linux Kernel mainline version 2.6.30 (2009, June 10)/[2] It is currently one of four standard Linux Security Modules (LSM), along with SELinux, AppArmor and SMACK.

The Tomoyo Linux project started as a patch for the Linux kernel to provide MAC. Porting Tomoyo Linux to the mainline Linux kernel required the introduction of hooks[3] into the LSM that had been designed and developed specifically to support SELinux and its label-based approach.

However, more hooks are needed to integrate the remaining MAC functionality of Tomoyo Linux. Consequently, the project is following two parallel development lines:

{{columns|colwidth=30em|col1=
  • Tomoyo Linux 1.x, original version
    • uses purposely created non-standard hooks
    • fully featured MAC
    • released as a patch for Linux kernel – Since this version 1.x does not depend on LSM, it can be used with Linux kernel 2.6 (starting from version 2.6.11) as well as 2.4.
    • latest version: 1.7.1

|col2=
  • Tomoyo Linux 2.x, mainline version
    • uses standard LSM hooks
    • fewer features
    • integral part of Linux kernel version 2.6.30
    • latest version: 2.5.0 included in Linux kernel 3.2

|col3=
  • Akari (stylised as AKARI), Tomoyo 1.x fork
    • uses standard LSM hooks
    • fewer features than Tomoyo 1.x, but more than Tomoyo 2.x
    • released as LSM, so no recompilation of the kernel is necessary

}}

References

1. ^{{cite web|url=http://tomoyo.osdn.jp/ |title=Tomoyo Linux Home Page |publisher=Tomoyo.osdn.jp |date= |accessdate=2013-05-23}}
2. ^{{cite web |title=Tomoyo Linux, an alternative Mandatory Access Control |publisher=Linux Kernel Newbies |work=Linux 2 6 30 |url=http://kernelnewbies.org/Linux_2_6_30#head-eeb259e0ba81d96d59015b8f79456d9a5283c650}}
3. ^{{cite web |title=Tomoyo #14 patch submission to LKML |publisher=LWN.net |url=https://lwn.net/Articles/313346/}}

External links

  • Comparison chart of 1.x and 2.x
  • Comparison chart of Tomoyo 1.x, 2.x, and Akari
  • Tomoyo Linux project
  • Tomoyo Linux at Embedded Linux Wiki
  • [https://lwn.net/Articles/277833/ LWN : Tomoyo Linux and pathname-based security]
  • Tomoyo – Debian Wiki
  • [https://wiki.archlinux.org/index.php/TOMOYO_Linux Tomoyo Linux – ArchWiki]
{{Linux kernel}}{{DEFAULTSORT:Tomoyo Linux}}

3 : Linux security software|Linux kernel features|Nippon Telegraph and Telephone

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/9/22 9:38:21