课程: Ubuntu Linux: Operating System Basics
今天就学习课程吧!
今天就开通帐号,24,700 门业界名师课程任您挑!
Explore AppArmor
- [Instructor] AppArmor is a kernel module using the Linux security module's interface, it provides mandatory access control to be added to programs, determining which specific file paths and resources it can or cannot use. Programs and services often have their own user in order to control what access they have to the system, to some degree; but many run as root and, as such, have access to anything on the system. Rather than using user level security to control what programs can do, AppArmor allows us to specify exactly what a program can and cannot access with a much higher degree of precision. We can see what's going on with AppArmor with the AppArmor status command. Specific settings for individual programs are called profiles, and I can see that 24 profiles are loaded on my system and 24 profiles are in enforce mode. Enforce mode applies the policy to the process, preventing access where it needs to. Another option, complain mode, doesn't enforce the policy. It allows a process…