Gentoo Archives: gentoo-hardened

From: Joshua Brindle <method@g.o>
To: "Dickenson, Toby" <tdickenson@×××××××××××××××××.com>, gentoo-hardened@g.o
Subject: Re: [gentoo-hardened] systrace observations
Date: Thu, 03 Apr 2003 17:05:05
Message-Id: 20030403T110511Z_B95E00150000@gentoo.org
1 answer #1: see bug #18690
2 answer #2: it's added to hardened-sources, which will soon host all the patches
3 for this project, as well as extra security/stability and stable performance patches.
4
5 i'd like more details, we have a couple people (natey in particular) working on systrace
6 and i'm sure he'd like to know what your problem is and look into fixing it.
7 the best way to get something like this in the system is to write a bug.
8
9 we have long term goals for systrace including writing policies for the bulk
10 of daemons in portage, and adding support for systrace to start-stop-daemon
11 (see bug #18430)
12
13 if you'd like to talk to us about the project or goals with systrace come by
14 #gentoo-hardened on freenode :)
15
16 cheers
17
18
19 Joshua Brindle
20
21 >>> Toby Dickenson <tdickenson@×××××××××××××××××.com> 04/03/03 09:55AM >>>
22 This last week I have been taking a look at systrace, since first hearing
23 about it on this list. For a while I have been looking for a "better chroot"
24 for securing some daemons, and I think systrace could be it.
25
26 Maintaining a systrace policy for a large daemon (I am working with Zope) is
27 easier than for chroot, because there is no need to maintain a seperate set
28 of files (or bind mounts) for the jail. This is particularly obvious when
29 there are multiple instances of each daemon.... They can share one systrace
30 policy, but a chroot solution would need seperate jails for each instance.
31
32 The performance impact seems negligible, and the ability to log the use of
33 incidental system calls is an unexpected bonus for intrusion detection.
34
35
36 Is anyone looking at merging systrace with gentoo-sources? The 2003-03-22
37 patch has some easily resolved conflicts when merged with gentoo-sources, it
38 compiles fine, but systrace doesnt function correctly when stressed. (more
39 details available on request).
40
41 --
42 Toby Dickenson
43 http://www.geminidataloggers.com/people/tdickenson
44
45 --
46 gentoo-hardened@g.o mailing list
47
48
49 --
50 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] systrace observations Toby Dickenson <tdickenson@×××××××××××××××××.com>