Gentoo Archives: gentoo-hardened

From: Gavin Vess <Gavin@××××.com>
To: gentoo-hardened@g.o
Subject: Re: [gentoo-hardened] ACL implementations
Date: Sun, 23 Mar 2003 06:12:44
Message-Id: 030c01c2f103$8077dc90$6788f7d1@epox2
In Reply to: [gentoo-hardened] ACL implementations by Joshua Brindle
1 Project "VITALITY" (~popularity) of leading projects relating to Linux ACL
2 ======================================================
3 (Hit counts from Google for search terms below.)
4 24,300 selinux
5 23,000 LIDS Linux
6 21,100 LSM linux security [I added 'security' since lsm matched many unrelated things]
7 8,090 grsecurity linux
8 4,770 systrace linux
9 3,590 WOLK linux [already in the portage tree under kernel sources]
10 2,790 linsec linux
11
12 Bulleted executive summaries for the above: http://www.rstack.org/oudot/rmll/slides/3/ksec_lsm.pdf (page 43+). Popularity is obviously not direct evidence of quality, *appropriateness* for Gentoo community, usability, etc., but might be correlated with these factors. Younger projects might also be on the rise (not reflected above). These products differ dramatically in features and purpose. One line summaries, with URLs: http://www.linuxsecurity.com/feature_stories/feature_story-134.html#5
13
14 >From a security conference:
15 http://216.239.33.100/search?q=cache:qLhr5OQLg_8C:www.rstack.org/oudot/rmll/+grsecurity+systrace+lids+se+selinux&hl=en&ie=UTF-8
16 (No highlighting: http://www.rstack.org/oudot/rmll/)
17
18 Cheers,
19 Gavin
20
21 More Comparisons
22 =================
23
24 systrace vs. LSM
25 - http://lwn.net/Articles/17170/
26 - rumors of a systrace module for LSM
27
28 grsecurity vs. lids:
29 - http://www.der-keiler.de/Mailing-Lists/linuxsecurity/2002-12/0032.html
30 - http://www.spinics.net/lists/security/msg01099.html
31
32 openwall
33 - excluded from this comparison since only a test release exists for 2.4 kernel
34
35 many more via Google
36
37 --
38 gentoo-hardened@g.o mailing list