How SELinux Can Help To Improve Server Security
The United States National Security Agency has developed SELinux as a research security architecture prototype. It is integrated to the 2.6.x Linux kernel using the Linux Security Modules (LSM) to enhance the security of the system. Security-enhanced Linux (SELinux) implements the FLASK security architecture, which has been used in a number of operating systems. The FLASK is very flexible that it allows the security server to be modified or even replaced. The security policies are encapsulated within the security server and this reduces the impact on the rest of the system. SELinux enforces MAC policies and these policies grant limited privilege for the user and the process to use resources for executing the assigned task.
How SELinux works?
The SELinux mechanism works by separating the information on the basis of confidentiality and integrity requirements. The MAC policies confine the amount of privilege to the user and processes to execute a particular task, which helps in reducing the harm caused by malicious programs and system daemons when compromised. This mechanism is different from the traditional Linux access control mechanisms and does not have “root” super-user concepts. The correctness of the kernel and the security policy configuration are the main factors on which the security of the SELinux depends. This saves the whole system from being affected by any action from the user programs or daemons.
Security Server Model
The server model of SELinux primarily takes into account the three relevant securities attributes – an identity, a role, and a type. SELinux assigns a three string context consisting of a role, user name, and domain (or type) to a current process. The combinations of these attributes are used to create the security context. The mapping between files and the security contexts is called labeling and these security contexts are used to work out the access decisions. Every process in the system has an identity associated with it. This helps the user to find his real identity, whenever he logs in the SELinux, and these SELinux identities are orthogonal to Linux UIDs. The SELinux identity of a process remains the same even if the UID of the process is changed. The identity of all the programs will be preserved, which makes it possible to provide the correct access decision for the right identity.
The SELinux uses a number of security policies to determine the restrictions and control the transition between the roles. A single policy file can be produced by combing the SELinux tools with the mapping file, a rule file, and an interface file. You can make these policies active by uploading it to the kernel. The loading or unloading the policies are very simple and does not even require a reboot. Some permission can be granted manually, without making any changes to the policies. By configuring the security policies you can limit the transition and this ensures that roles changes occur only with the consent of the explicit user and not by executing some malware. SELinux uses the RBAC policy to describe the allowable actions for a particular role and when these policies are configured in the right way, they can be used to directly specify permissions granted to roles and domains that can be used by roles. For the first time, these well defined policies are tested in the permissive mode.
The SELinux provide finer-grained permissions, when compared to the TE policy. The system supports flexible policies and allows the admin to make changes in the policies. The class concept used by the SELinux helps the policy to differentiate dissimilar kinds of objects. This allows the admin to grant different permissions to different objects in the same file.

The network of networks i.e. the internet has undergone a new and revolutionary change by the end of 1999. Till that day it was just meant to connect people and they have to be satisfied with the read only feature. The regular users were only allowed to read the information from websites, which was too mind-numbing. Today, people use interactive programs like chat to communicate with others, which helps them to know everything they need at the same time they produce the query. The web 2.0 came with this remarkable change in the web. The new web 2.0 technique is used in almost all fields and has also helped great deal in increasing the business turnover.







