发明名称 EXTENDING SELINUX POLICY WITH ENFORCEMENT OF FILE NAME TRANSLATIONS
摘要 An operating system identifies a request of a process to create a new object with a name in a file system of the processing device. The operating system identifies a policy rule applicable to the new object in view of at least the name of the new object. The operating system creates a label for the new object using the applicable policy rule and associates the new object with the created label.
申请公布号 US2015304357(A1) 申请公布日期 2015.10.22
申请号 US201514754411 申请日期 2015.06.29
申请人 Red Hat, Inc. 发明人 Paris Eric;Walsh Daniel J.
分类号 H04L29/06;H04L29/08 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method comprising: identifying, by a processing device, a request of a process to create a new object in a file system of the processing device, the new object having a name; identifying, by the processing device, a policy rule applicable to the new object in view of at least the name of the new object; creating, by the processing device, a label for the new object using the applicable policy rule in view of at least the name of the new object; and associating, by the processing device, the new object with the created label.
地址 Raleigh NC US