ããã«ã¡ã¯ãã¿ããªïŒ ç¹ã«ã³ãŒã¹ã®åŠçã«ãšã£ãŠã¯
SELinux ãããžã§ã¯ãã«é¢ããŠæãããå¯ãããã質åã®ããã€ãã«çããŠã¿ãŸããã çŸåšã質å㯠XNUMX ã€ã®äž»èŠãªã«ããŽãªã«åé¡ãããŠããŸãã ãã¹ãŠã®è³ªåãšåçãèšèŒãããŠããŸã
ÐбзПÑ
ÐбзПÑ
- ã»ãã¥ãªãã£åŒ·åããã Linux ãšã¯äœã§ãã?
Security-enhanced Linux (SELinux) ã¯ãæè»ã§åŒ·å¶çãªã¢ã¯ã»ã¹å¶åŸ¡ãå®çŸãã Flask ã»ãã¥ãªã㣠ã¢ãŒããã¯ãã£ã®ãªãã¡ã¬ã³ã¹å®è£ ã§ãã ããã¯ãæè»ãªåŒ·å¶ã¡ã«ããºã ã®æçšæ§ãšããã®ãããªã¡ã«ããºã ããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã«è¿œå ããæ¹æ³ãå®èšŒããããã«äœæãããŸããã ãã®åŸãFlask ã¢ãŒããã¯ãã£ã¯ Linux ã«çµ±åãããSolaris ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ãFreeBSD ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ãDarwin ã«ãŒãã«ãªã©ã®ä»ã®ããã€ãã®ã·ã¹ãã ã«ç§»æ€ãããå¹ åºãé¢é£äœæ¥ãçãŸããŸããã Flask ã¢ãŒããã¯ãã£ã¯ãã¿ã€ã匷å¶ãããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ãããã³ãã«ãã¬ãã« ã»ãã¥ãªãã£ã®æŠå¿µã«åºã¥ãããªã·ãŒãå«ããããŸããŸãªçš®é¡ã®åŒ·å¶ã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒã匷å¶ããããã®äžè¬çãªãµããŒããæäŸããŸãã - ã»ãã¥ãªãã£ã匷åããã Linux ã§ã¯ãæšæºã® Linux ã§ã¯æäŸã§ããªããã®ã¯äœã§ãããã?
ã»ãã¥ãªãã£ã匷åããã Linux ã«ãŒãã«ã¯ããŠãŒã¶ãŒ ããã°ã©ã ãšã·ã¹ãã ãµãŒããŒãããžã§ãã®å®è¡ã«å¿ èŠãªæå°éã®æš©éã»ããã«å¶éããã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒã匷å¶ããŸãã ãã®å¶éã«ããã(ãããã¡ ãªãŒããŒãããŒãæ§æãã¹ãªã©ã«ãã) 䟵害ãçºçããå Žåã«ããããã®ãŠãŒã¶ãŒ ããã°ã©ã ãã·ã¹ãã ããŒã¢ã³ã害ãåãŒãèœåãäœæžãŸãã¯æé€ãããŸãã ãã®å¶éã¡ã«ããºã ã¯ãåŸæ¥ã® Linux ã¢ã¯ã»ã¹å¶åŸ¡ã¡ã«ããºã ãšã¯ç¬ç«ããŠæ©èœããŸãã ããã«ã¯ãrootãã¹ãŒããŒãŠãŒã¶ãŒã®æŠå¿µããªããåŸæ¥ã® Linux ã»ãã¥ãªã㣠ã¡ã«ããºã ã®ããç¥ãããæ¬ ç¹ (setuid/setgid ãã€ããªãžã®äŸåãªã©) ãå ±æããŸããã
å€æŽãããŠããªã Linux ã·ã¹ãã ã®ã»ãã¥ãªãã£ã¯ãã«ãŒãã«ããã¹ãŠã®ç¹æš©ã¢ããªã±ãŒã·ã§ã³ãããã³ãããã®åæ§æã®æ£ç¢ºãã«äŸåããŸãã ãããã®é åã®ããããã«åé¡ããããšãã·ã¹ãã å šäœãå±éºã«ãããããå¯èœæ§ããããŸãã å¯Ÿç §çã«ãã»ãã¥ãªãã£ã匷åããã Linux ã«ãŒãã«ã«åºã¥ããŠå€æŽãããã·ã¹ãã ã®ã»ãã¥ãªãã£ã¯ãäž»ã«ã«ãŒãã«ã®æ£ç¢ºããšãã®ã»ãã¥ãªã㣠ããªã·ãŒã®æ§æã«äŸåããŸãã ã¢ããªã±ãŒã·ã§ã³ã®æ£ç¢ºæ§ãæ§æã«åé¡ããããšãåã ã®ãŠãŒã¶ãŒ ããã°ã©ã ãã·ã¹ãã ããŒã¢ã³ãéå®çã«äŸµå®³ãããå¯èœæ§ããããŸãããä»ã®ãŠãŒã¶ãŒ ããã°ã©ã ãã·ã¹ãã ããŒã¢ã³ããŸãã¯ã·ã¹ãã å šäœã®ã»ãã¥ãªãã£ã«ã»ãã¥ãªã㣠ãªã¹ã¯ãçããããšã¯ãããŸããã - 圌女ã¯äœã®åœ¹ã«ç«ã€ã®ã§ããïŒ
Linux ã®æ°ããã»ãã¥ãªãã£åŒ·åæ©èœã¯ãæ©å¯æ§ãšæŽåæ§ã®èŠä»¶ã«åºã¥ããŠæ å ±ãåé¢ããããã«èšèšãããŠããŸãã ãããã¯ãããã»ã¹ãããŒã¿ãããã°ã©ã ãèªã¿åã£ãããããŒã¿ãããã°ã©ã ãæ¹ããããããã¢ããªã±ãŒã·ã§ã³ ã»ãã¥ãªã㣠ã¡ã«ããºã ããã€ãã¹ããããä¿¡é Œã§ããªãããã°ã©ã ãå®è¡ããããã·ã¹ãã ã»ãã¥ãªã㣠ããªã·ãŒã«éåããŠä»ã®ããã»ã¹ã劚害ãããããããšãé²ãããã«èšèšãããŠããŸãã ãŸãããã«ãŠã§ã¢ããã°ã®ããããã°ã©ã ã«ãã£ãŠåŒãèµ·ããããå¯èœæ§ã®ããæœåšçãªæ害ãå¶éããã®ã«ã圹ç«ã¡ãŸãã ãŸããç°ãªãã»ãã¥ãªãã£æš©éãæã€ãŠãŒã¶ãŒãåãã·ã¹ãã ã䜿çšããŠãã»ãã¥ãªãã£èŠä»¶ãæãªãããšãªããç°ãªãã»ãã¥ãªãã£èŠä»¶ãæã€ç°ãªãçš®é¡ã®æ å ±ã«ã¢ã¯ã»ã¹ã§ããããã«ããããã«ã圹ç«ã¡ãŸãã - ã³ããŒãå
¥æããã«ã¯ã©ãããã°ããã§ãã?
å€ãã® Linux ãã£ã¹ããªãã¥ãŒã·ã§ã³ã«ã¯ãããã©ã«ãã®æ©èœãŸãã¯ãªãã·ã§ã³ã®ããã±ãŒãžãšã㊠SELinux ã®ãµããŒãããã§ã«çµã¿èŸŒãŸããŠããŸãã ã³ã¢ SELinux ãŠãŒã¶ãŒã©ã³ã ã³ãŒãã¯ã次ã®å Žæããå ¥æã§ããŸããGitHubã® ã ãšã³ããŠãŒã¶ãŒã¯éåžžããã£ã¹ããªãã¥ãŒã·ã§ã³ã«ãã£ãŠæäŸãããããã±ãŒãžã䜿çšããå¿ èŠããããŸãã - ãªãªãŒã¹ã«ã¯äœãå«ãŸããŠããŸãã?
SELinux ã® NSA ãªãªãŒã¹ã«ã¯ãã³ã¢ SELinux ãŠãŒã¶ãŒã©ã³ã ã³ãŒããå«ãŸããŠããŸãã SELinux ã®ãµããŒãã¯ãkernel.org ããå ¥æã§ããã¡ã€ã³ã¹ããªãŒã Linux 2.6 ã«ãŒãã«ã«ãã§ã«çµã¿èŸŒãŸããŠããŸãã ã³ã¢ SELinux ãŠãŒã¶ãŒã©ã³ã ã³ãŒãã¯ããã€ã㪠ããªã·ãŒæäœçšã®ã©ã€ãã©ãª (libsepol)ãããªã·ãŒ ã³ã³ãã€ã© (checkpolicy)ãã»ãã¥ãªã㣠ã¢ããªã±ãŒã·ã§ã³çšã®ã©ã€ãã©ãª (libselinux)ãããªã·ãŒç®¡çããŒã«çšã®ã©ã€ãã©ãª (libsemanage)ãããã³ããã€ãã®ããªã·ãŒé¢é£ãŠãŒãã£ãªã㣠(ããªã·ãŒã³ã¢ãŠãŒãã£ãªãã£)ã
SELinux ã䜿çšããã«ã¯ãSELinux 察å¿ã«ãŒãã«ãšåºæ¬çãªãŠãŒã¶ãŒã©ã³ã ã³ãŒãã«å ããŠãããªã·ãŒãš SELinux ããããé©çšããããŠãŒã¶ãŒã¹ããŒã¹ ããã±ãŒãžãå¿ èŠã§ãã ããªã·ãŒã¯æ¬¡ããååŸã§ããŸããSELinux ãªãã¡ã¬ã³ã¹ ããªã·ãŒ ãããžã§ã¯ã . - 匷åããã Linux ãæ¢åã® Linux ã·ã¹ãã ã«ã€ã³ã¹ããŒã«ã§ããŸãã?
ã¯ããSELinux ã®å€æŽãæ¢åã® Linux ã·ã¹ãã ã«ã®ã¿ã€ã³ã¹ããŒã«ããããšããSELinux ãµããŒãããã§ã«å«ãŸããŠãã Linux ãã£ã¹ããªãã¥ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ããããšãã§ããŸãã SELinux ã¯ãSELinux ããµããŒããã Linux ã«ãŒãã«ãã©ã€ãã©ãªãšãŠãŒãã£ãªãã£ã®ã³ã¢ ã»ãããããã€ãã®å€æŽããããŠãŒã¶ãŒ ããã±ãŒãžãããã³ããªã·ãŒæ§æã§æ§æãããŸãã SELinux ãµããŒãã®ãªãæ¢åã® Linux ã·ã¹ãã ã«ã€ã³ã¹ããŒã«ããã«ã¯ããœãããŠã§ã¢ãã³ã³ãã€ã«ã§ãããã®ä»ã®å¿ èŠãªã·ã¹ãã ããã±ãŒãžãå¿ èŠã§ãã Linux ãã£ã¹ããªãã¥ãŒã·ã§ã³ã«ãã§ã« SELinux ã®ãµããŒããå«ãŸããŠããå Žåã¯ãSELinux ã® NSA ãªãªãŒã¹ããã«ããŸãã¯ã€ã³ã¹ããŒã«ããå¿ èŠã¯ãããŸããã - ã»ãã¥ãªãã£ã匷åããã Linux ãšç¡ä¿®æ£ã® Linux ã«ã¯ã©ã®çšåºŠã®äºææ§ããããŸãã?
ã»ãã¥ãªãã£ã匷åããã Linux ã¯ãæ¢åã® Linux ã¢ããªã±ãŒã·ã§ã³ããã³æ¢åã® Linux ã«ãŒãã« ã¢ãžã¥ãŒã«ãšã®ãã€ããªäºææ§ãæäŸããŸãããäžéšã®ã«ãŒãã« ã¢ãžã¥ãŒã«ã¯ SELinux ãšé©åã«å¯Ÿè©±ããããã«å€æŽãå¿ èŠãªå ŽåããããŸãã ããã XNUMX ã€ã®äºææ§ã«ããŽãªã«ã€ããŠã¯ã以äžã§è©³ãã説æããŸãã- ã¢ããªã±ãŒã·ã§ã³ã®äºææ§
SELinux ã¯ãæ¢åã®ã¢ããªã±ãŒã·ã§ã³ãšã®ãã€ããªäºææ§ãæäŸããŸãã æ°ããã»ãã¥ãªãã£å±æ§ãå«ãããã«ã«ãŒãã« ããŒã¿æ§é ãæ¡åŒµããã»ãã¥ãªã㣠ã¢ããªã±ãŒã·ã§ã³çšã®æ°ãã API åŒã³åºããè¿œå ããŸããã ãã ããã¢ããªã±ãŒã·ã§ã³ããèŠããããŒã¿æ§é ã¯äžåå€æŽããŠããããæ¢åã®ã·ã¹ãã ã³ãŒã«ã®ã€ã³ã¿ãŒãã§ã€ã¹ãå€æŽããŠããªããããã»ãã¥ãªã㣠ããªã·ãŒã§èš±å¯ãããŠããéããæ¢åã®ã¢ããªã±ãŒã·ã§ã³ã¯åŒãç¶ãå®è¡ã§ããŸãã - ã«ãŒãã«ã¢ãžã¥ãŒã«ã®äºææ§
åœåãSELinux ã¯æ¢åã®ã«ãŒãã« ã¢ãžã¥ãŒã«ã«å¯ŸããŠåæäºææ§ã®ã¿ãæäŸããŠããŸããã ã«ãŒãã« ããŒã¿æ§é ã«è¿œå ãããæ°ããã»ãã¥ãªã㣠ãã£ãŒã«ããååŸããã«ã¯ãã«ãŒãã« ããããŒãå€æŽããŠãã®ãããªã¢ãžã¥ãŒã«ãåã³ã³ãã€ã«ããå¿ èŠããããŸããã LSM ãš SELinux ã¯äž»æµã® Linux 2.6 ã«ãŒãã«ã«çµ±åãããŠãããããSELinux ã¯æ¢åã®ã«ãŒãã« ã¢ãžã¥ãŒã«ãšã®ãã€ããªäºææ§ãæäŸããŸãã ãã ããäžéšã®ã«ãŒãã« ã¢ãžã¥ãŒã«ã¯ãå€æŽãå ããªããš SELinux ãšé©åã«é£æºã§ããªãå ŽåããããŸãã ããšãã°ãã«ãŒãã« ã¢ãžã¥ãŒã«ãéåžžã®åæåé¢æ°ã䜿çšããã«ã«ãŒãã« ãªããžã§ã¯ããçŽæ¥å²ãåœãŠãŠã»ããã¢ããããå Žåãã«ãŒãã« ãªããžã§ã¯ãã¯é©åãªã»ãã¥ãªãã£æ å ±ãæããªãå¯èœæ§ããããŸãã äžéšã®ã«ãŒãã« ã¢ãžã¥ãŒã«ã«ã¯ããã®åäœã«å¯Ÿããé©åãªã»ãã¥ãªãã£å¶åŸ¡ãæ¬ ããŠããå ŽåããããŸãã ã«ãŒãã«é¢æ°ãŸãã¯æš©éé¢æ°ãžã®æ¢åã®åŒã³åºãã SELinux æš©éãã§ãã¯ãããªã¬ãŒããŸãããMAC ããªã·ãŒãé©çšããã«ã¯ããã詳现ãªå¶åŸ¡ãŸãã¯è¿œå ã®å¶åŸ¡ãå¿ èŠã«ãªãå ŽåããããŸãã
å¿ èŠãªãã¹ãŠã®æäœãã»ãã¥ãªã㣠ããªã·ãŒæ§æã§èš±å¯ãããŠããå Žåãã»ãã¥ãªãã£ã匷åããã Linux ã§ã¯ãéåžžã® Linux ã·ã¹ãã ãšã®çžäºéçšæ§ã®åé¡ãçºçããããšã¯ãããŸããã
- ã¢ããªã±ãŒã·ã§ã³ã®äºææ§
- ã»ãã¥ãªã㣠ããªã·ãŒæ§æäŸã®ç®çã¯äœã§ãã?
倧ãŸãã«èšãã°ã匷å¶çãªã¢ã¯ã»ã¹å¶åŸ¡ã®æè»æ§ãšã»ãã¥ãªãã£ãå®èšŒããã¢ããªã±ãŒã·ã§ã³ã®å€æŽãæå°éã«æããã·ã³ãã«ãªåäœã·ã¹ãã ãæäŸããããšãç®æšã§ãã äžäœã¬ãã«ã§ã¯ãããªã·ãŒã«ã¯äžé£ã®ç®æšããããããã«ã€ããŠã¯ããªã·ãŒã®ããã¥ã¡ã³ãã«èšèŒãããŠããŸãã ãããã®ç®æšã«ã¯ãçããŒã¿ãžã®ã¢ã¯ã»ã¹ã®å¶åŸ¡ãã«ãŒãã«ãã·ã¹ãã ãœãããŠã§ã¢ãã·ã¹ãã æ§ææ å ±ããã³ã·ã¹ãã ãã°ã®æŽåæ§ã®ä¿è·ãç¹æš©ãå¿ èŠãšããããã»ã¹ã®è匱æ§ã®æªçšã«ãã£ãŠåŒãèµ·ããããå¯èœæ§ã®ããæœåšçãªæ害ã®å¶éãæªæã®ããããã»ã¹ã®å®è¡ããã®ç¹æš©ããã»ã¹ã®ä¿è·ãªã©ãå«ãŸããŸããã³ãŒãã䜿çšããŠããŠãŒã¶ãŒèªèšŒãªãã§ç®¡çè ããŒã«ãšãã¡ã€ã³ããã°ã€ã³ã§ããªãããã«ä¿è·ããéåžžã®ãŠãŒã¶ãŒ ããã»ã¹ãã·ã¹ãã ãŸãã¯ç®¡çããã»ã¹ã«å¹²æžããã®ãé²ããæªæã®ããã¢ãã€ã« ã³ãŒãã«ãããã©ãŠã¶ã®è匱æ§æªçšãããŠãŒã¶ãŒãšç®¡çè ãä¿è·ããŸãã - Linux ãããŒã¹ ãã©ãããã©ãŒã ãšããŠéžã°ããã®ã¯ãªãã§ãã?
Linux ã¯ããã®æåã®æ¡å€§ãšãªãŒãã³ãªéçºç°å¢ã®ããããã®äœæ¥ã®æåã®ãªãã¡ã¬ã³ã¹å®è£ ã®ãã©ãããã©ãŒã ãšããŠéžæãããŸããã Linux ã¯ããã®æ©èœããã¹ã ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã äžã§æåããåæã«åºã䜿çšãããŠããã·ã¹ãã ã®ã»ãã¥ãªãã£ã«è²¢ç®ã§ããããšãå®èšŒãã絶奜ã®æ©äŒãšãªããŸãã Linux ãã©ãããã©ãŒã ã¯ããã®ç 究ãå¯èœãªéãå¹ åºãèŠéãåŸã絶奜ã®æ©äŒã§ããããããããä»ã®æ奜家ã«ããè¿œå ã®ã»ãã¥ãªãã£ç 究ã®åºç€ãšããŠãæ©èœããŸãã - ãªããã®ä»äºãããã®ã§ããïŒ
åœç«æ å ±ã»ãã¥ãªãã£ç 究æ åœå®¶å®å šä¿éå±ã¯ãNSA ãç±³åœã®åœå®¶å®å šä¿éäžã®å©çã«ãšã£ãŠéèŠãªæ å ±ã€ã³ãã©ã¹ãã©ã¯ãã£ã«æ å ±ã»ãã¥ãªã㣠ãœãªã¥ãŒã·ã§ã³ã補åããµãŒãã¹ãæäŸã§ããããã«ããããã®ç 究ãšé«åºŠãªæè¡éçºãæ åœããŠããŸãã
å®è¡å¯èœãªå®å šãªãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ãäœæããããšã¯ãäŸç¶ãšããŠå€§ããªç 究課é¡ã§ãã ç§ãã¡ã®ç®æšã¯ãã»ãã¥ãªãã£ã«å¿ èŠãªãµããŒããæäŸãããŠãŒã¶ãŒã«å¯ŸããŠã»ãŒééçãªæ¹æ³ã§ããã°ã©ã ãå®è¡ãããã³ããŒã«ãšã£ãŠé åçãªå¹ççãªã¢ãŒããã¯ãã£ãäœæããããšã§ãã ãã®ç®æšãéæããããã®éèŠãªã¹ãããã¯ã匷å¶ã¢ã¯ã»ã¹å¶åŸ¡ã¡ã«ããºã ãã¡ã€ã³ã®ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã«ã©ã®ããã«çµ±åã§ããããå®èšŒããããšã§ãããšç§ãã¡ã¯èããŠããŸãã - ããã¯ä»¥åã® OS NSA ã®èª¿æ»ãšã©ã®ããã«é¢é£ããŠããŸãã?
NSA åœå®¶ä¿èšŒç 究æã®ç 究è ã¯ãã»ãã¥ã¢ ã³ã³ãã¥ãŒãã£ã³ã° ã³ãŒãã¬ãŒã·ã§ã³ (SCC) ãšææºããŠãLOCK ã·ã¹ãã ã«ãã£ãŠå é§ããããã¡ã«ããºã ã§ããã¿ã€ãæœè¡ã«åºã¥ã匷åã§æè»ãªæœè¡ã¢ãŒããã¯ãã£ãéçºããŸããã NSA ãš SCC ã¯ãMach ã«åºã¥ã XNUMX ã€ã®ãããã¿ã€ã ã¢ãŒããã¯ãã£ãDTMach ãš DTOS (http://www.cs.utah.edu/flux/dtos/ ïŒã ãã®åŸãNSA ãš SCC ã¯ãŠã¿å€§åŠã® Flux Research Group ãšååããŠãã¢ãŒããã¯ãã£ã Fluke Research ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã«ç§»æ€ããŸããã ãã®ç§»è¡äžã«ãåçãªã»ãã¥ãªã㣠ããªã·ãŒã®ãµããŒãã匷åããããã«ã¢ãŒããã¯ãã£ãæ¹è¯ãããŸããã ãã®æ¹è¯ãããã¢ãŒããã¯ãã£ã¯ Flask (http://www.cs.utah.edu/flux/flask/ ïŒã çŸåšãNSA 㯠Flask ã¢ãŒããã¯ãã£ã Linux ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã«çµ±åãããã®ãã¯ãããžãŒãããåºç¯ãªéçºè ããã³ãŠãŒã¶ãŒ ã³ãã¥ããã£ã«æäŸããŠããŸãã - ã»ãã¥ãªãã£ã匷åããã Linux ã¯ä¿¡é Œã§ãããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã§ãã?
ãä¿¡é Œã§ãããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ããšããèªå¥ã¯ãäžè¬ã«ãæ¿åºã®ç¹å®ã®èŠä»¶ãæºããããã«ãéå±€åãããã»ãã¥ãªãã£ãšæ€èšŒã«å¯ŸããååãªãµããŒããæäŸãããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ãæããŸãã ã»ãã¥ãªãã£ã匷åããã Linux ã«ã¯ããããã®ã·ã¹ãã ããã®æçãªæŽå¯ãçµã¿èŸŒãŸããŠããŸããã匷å¶çãªã¢ã¯ã»ã¹å¶åŸ¡ã«éç¹ã眮ãããŠããŸãã ã»ãã¥ãªãã£ã匷åããã Linux ãéçºããæ¬æ¥ã®ç®çã¯ããã®ãã¯ãããžãå®èšŒããããã«ãçŸå®äžçã®ããŸããŸãªç°å¢ã§ç®ã«èŠããã»ãã¥ãªãã£äžã®å©ç¹ãæäŸãã䟿å©ãªæ©èœãäœæããããšã§ããã SELinux èªäœã¯ä¿¡é Œã§ãããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã§ã¯ãããŸããããä¿¡é Œã§ãããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã«å¿ èŠãªéèŠãªã»ãã¥ãªãã£æ©èœã§ãã匷å¶ã¢ã¯ã»ã¹å¶åŸ¡ãæäŸããŸãã SELinux ã¯ãLabeled Security Protection Profile ã«åŸã£ãŠè©äŸ¡ããã Linux ãã£ã¹ããªãã¥ãŒã·ã§ã³ã«çµ±åãããŠããŸãã ãã¹ãæžã¿ããã³ãã¹ãæžã¿ã®è£œåã«é¢ããæ å ±ã¯ã次ã®ãµã€ãã§ã芧ããã ããŸããhttp://niap-ccevs.org/ . - 圌女ã¯æ¬åœã«å®ãããŠããã®ã§ããããïŒ
å®å šãªã·ã¹ãã ã®æŠå¿µã«ã¯å€ãã®å±æ§ (ç©ççãªã»ãã¥ãªãã£ã人çã»ãã¥ãªãã£ãªã©) ãå«ãŸããŠããŸãããã»ãã¥ãªãã£ã匷åããã Linux ã¯ããããã®å±æ§ã®éåžžã«çãã»ãã (ã€ãŸãããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã®åŒ·å¶å¶åŸ¡) ã®ã¿ã«å¯Ÿå¿ããŸãã èšãæããã°ããå®å šãªã·ã¹ãã ããšã¯ãçŸå®äžçã®äžéšã®æ å ±ããæ å ±ã®ææè ããã³/ãŸãã¯ãŠãŒã¶ãŒãèŠåãããå®éã®æµããä¿è·ããã®ã«ååãªå®å šæ§ãæå³ããŸãã ã»ãã¥ãªãã£ã匷åããã Linux ã¯ãLinux ã®ãããªææ°ã®ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã«å¿ èŠãªã³ã³ãããŒã«ã玹ä»ããããšã ããç®çãšããŠãããããããèªäœãå®å šãªã·ã¹ãã ã®èå³æ·±ãå®çŸ©ã«é©åããå¯èœæ§ã¯äœãã§ãã ã»ãã¥ãªãã£ã匷åããã Linux ã§å®èšŒãããæè¡ã¯ãã»ãã¥ã¢ãªã·ã¹ãã ãæ§ç¯ãã人ã ã«ãšã£ãŠåœ¹ç«ã€ãšä¿¡ããŠããŸãã - ä¿èšŒãæ¹åããããã«äœãããŸããã?
ãã®ãããžã§ã¯ãã®ç®æšã¯ãLinux ã«æå°éã®å€æŽãå ããŠåŒ·å¶ã¢ã¯ã»ã¹å¶åŸ¡ãè¿œå ããããšã§ããã ãã®æåŸã®ç®æšã¯ãä¿èšŒãæ¹åããããã«ã§ããããšãå€§å¹ ã«å¶éãããããLinux ã®ä¿èšŒãæ¹åããåãçµã¿ã¯è¡ãããŠããŸããã äžæ¹ããã®æ¹è¯ç¹ã¯ãé«ã»ãã¥ãªãã£ã®ã»ãã¥ãªã㣠ã¢ãŒããã¯ãã£ã®èšèšã«é¢ãã以åã®äœæ¥ã«åºã¥ããŠæ§ç¯ãããŠããããããã®èšèšååã®ã»ãšãã©ã¯ Security-enhanced Linux ã«åŒãç¶ãããŠããŸãã - CCEVS ã¯ã»ãã¥ãªãã£ã匷åããã Linux ãè©äŸ¡ããŸãã?
ã»ãã¥ãªãã£ã匷åããã Linux èªäœã¯ãã»ãã¥ãªã㣠ãããã¡ã€ã«ã§è¡šãããã»ãã¥ãªãã£åé¡ã®å®å šãªã»ããã«å¯ŸåŠããããã«èšèšãããŠããããã§ã¯ãããŸããã çŸåšã®æ©èœã®ã¿ãè©äŸ¡ããããšãå¯èœã§ããããã®ãããªè©äŸ¡ã®äŸ¡å€ã¯éãããŠãããšèããããŸãã ãã ããç§ãã¡ã¯ä»ã®äŒæ¥ãšååããŠãè©äŸ¡æžã¿ã® Linux ãã£ã¹ããªãã¥ãŒã·ã§ã³ããã³è©äŸ¡äžã® Linux ãã£ã¹ããªãã¥ãŒã·ã§ã³ã«ãã®ãã¯ãããžãçµã¿èŸŒãããšã«åãçµãã§ããŸããã ãã¹ãæžã¿ããã³ãã¹ãæžã¿ã®è£œåã«é¢ããæ å ±ã¯ã次ã®ãµã€ãã§ã芧ããã ããŸããhttp://niap-ccevs.org/ . - è匱æ§ãä¿®æ£ããããšããŸããã?
ããããç§ãã¡ã¯äœæ¥äžã«è匱æ§ãæ¢ãããçºèŠãããããŸããã§ããã ç§ãã¡ã¯ãæ°ããã®ã¢ãè¿œå ããã®ã«å¿ èŠãªæäœéã®ãã®ã ããæäŸããŸããã - ãã®ã·ã¹ãã ã¯æ¿åºã«ãã䜿çšãæ¿èªãããŠããŸãã?
ã»ãã¥ãªãã£ã匷åããã Linux ã«ã¯ãä»ã®ããŒãžã§ã³ã® Linux ã«å¯ŸããŠæ¿åºã«ãã䜿çšã«å¯Ÿããç¹å¥ãŸãã¯è¿œå ã®æ¿èªã¯ãããŸãããã»ãã¥ãªãã£ã匷åããã Linux ã«ã¯ãä»ã®ããŒãžã§ã³ã® Linux ã«æ¯ã¹ãŠæ¿åºã«ãã䜿çšã«å¯Ÿããç¹å¥ãŸãã¯è¿œå ã®æ¿èªããããŸããã - ããã¯ä»ã®åãçµã¿ãšã©ãéãã®ã§ããããïŒ
ã»ãã¥ãªãã£ã匷åããã Linux ã«ã¯ãããã€ãã®ãããã¿ã€ã ã·ã¹ãã (DTMachãDTOSãFlask) ã§å®éšçã«ãã¹ãããããæè»ãªåŒ·å¶ã¢ã¯ã»ã¹å¶åŸ¡ã®ããã®æ確ã«å®çŸ©ãããã¢ãŒããã¯ãã£ããããŸãã å¹ åºãã»ãã¥ãªã㣠ããªã·ãŒããµããŒãããã¢ãŒããã¯ãã£ã®èœåã«ã€ããŠè©³çŽ°ãªç 究ãè¡ãããŠããã以äžã§å©çšå¯èœã§ããhttp://www.cs.utah.edu/flux/dtos/ Оhttp://www.cs.utah.edu/flux/flask/ .
ãã®ã¢ãŒããã¯ãã£ã¯ãä»ã®ã·ã¹ãã ã§ã¯å¶åŸ¡ãããªãå€ãã®ã«ãŒãã«æœè±¡åãšãµãŒãã¹ã«å¯Ÿãããã现ããå¶åŸ¡ãæäŸããŸãã æ¡åŒµã»ãã¥ãªãã£ãåãã Linux ã·ã¹ãã ã®éç«ã£ãç¹æ§ã®ããã€ãã¯æ¬¡ã®ãšããã§ãã- ããªã·ãŒãšå·è¡æš©ã®çŽç²ãªåé¢
- æ確ã«å®çŸ©ãããããªã·ãŒã€ã³ã¿ãŒãã§ã€ã¹
- ç¹å®ã®ããªã·ãŒãããªã·ãŒèšèªããã®ç¬ç«
- ã»ãã¥ãªãã£ã©ãã«ã®ç¹å®ã®åœ¢åŒãå 容ããã®ç¬ç«
- ã«ãŒãã«ãªããžã§ã¯ããšãµãŒãã¹ã®åå¥ã®ã©ãã«ãšã³ã³ãããŒã«
- ã¢ã¯ã»ã¹æ±ºå®ã®ãã£ãã·ã¥ã«ããå¹çå
- ããªã·ãŒå€æŽã®ãµããŒã
- ããã»ã¹ã®åæåãšç¶æ¿ãããã³ããã°ã©ã å®è¡ã®å¶åŸ¡
- ãã¡ã€ã«ã·ã¹ãã ããã£ã¬ã¯ããªããã¡ã€ã«ãéããŠãããã¡ã€ã«ã®èª¬æã®ç®¡ç
- ãœã±ãããã¡ãã»ãŒãžããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ãŒã¹ã®ç®¡ç
- ãæ©äŒãã®äœ¿çšã®å¶åŸ¡
- ãã®ã·ã¹ãã ã®ã©ã€ã»ã³ã¹å¶éã¯äœã§ãã?
ãµã€ãäžã«ãããã¹ãŠã®ãœãŒã¹ã³ãŒãhttps://www.nsa.gov ãå ã®ãœãŒã¹ ã³ãŒããšåãæ¡ä»¶ã§é åžãããŸãã ããšãã°ãLinux ã«ãŒãã«ã®ä¿®æ£ããã°ã©ã ããããã§å ¥æã§ããæ¢åã®ãŠãŒãã£ãªãã£ã®å€ãã®ä¿®æ£ããã°ã©ã ã¯ã次ã®æ¡ä»¶ã«åºã¥ããŠãªãªãŒã¹ãããŸããGNU General Public LicenseïŒGPLïŒ . - 茞åºèŠå¶ã¯ãããŸãã?
Linux ã«ã¯ãä»ã®ããŒãžã§ã³ã® Linux ãšæ¯ã¹ãŠã»ãã¥ãªãã£ã匷åãããè¿œå ã®èŒžåºèŠå¶ã¯ãããŸããã - NSAã¯åœå
ã§ããã䜿çšããã€ããã§ãã?
æãããªçç±ãããNSA ã¯éçšäžã®äœ¿çšã«ã€ããŠã³ã¡ã³ãããŠããŸããã - Secure Computing Corporation ããã® 26 幎 2002 æ XNUMX æ¥ã®ä¿èšŒå£°æã¯ãSELinux ã GNU General Public License ã«åºã¥ããŠå©çšå¯èœã«ãªã£ããšãã NSA ã®ç«å Žãå€æŽããŸãã?
NSAã®ç«å Žã¯å€ãã£ãŠããªãã NSA ã¯ãSELinux ã®äœ¿çšãã³ããŒãé åžãå€æŽã«ã¯ GNU äžè¬å ¬è¡å©çšèš±è«Ÿå¥çŽæžã®æ¡é ãé©çšããããšäŸç¶ãšããŠä¿¡ããŠããŸãã CmãNSA ãã¬ã¹ãªãªãŒã¹ 2 幎 2001 æ XNUMX æ¥ . - NSA ã¯ãªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ããµããŒãããŠããŸãã?
NSA ã®ãœãããŠã§ã¢ ã»ãã¥ãªãã£ãžã®åãçµã¿ã¯ãããã©ã€ãšã¿ãª ãœãããŠã§ã¢ãšãªãŒãã³ ãœãŒã¹ ãœãããŠã§ã¢ã®äž¡æ¹ã«åã³ãç§ãã¡ã¯ç 究掻åã«ãããŠãããã©ã€ãšã¿ãª ã¢ãã«ãšãªãŒãã³ ãœãŒã¹ ã¢ãã«ã®äž¡æ¹ãããŸã䜿çšããŠããŸããã NSA ã®ãœãããŠã§ã¢ ã»ãã¥ãªãã£ãåäžãããåãçµã¿ã¯ãXNUMX ã€ã®åçŽãªèæ ®äºé ã«ãã£ãŠåæ©ä»ããããŠããŸããããã¯ãNSA ã®é¡§å®¢ã«æãåºã䜿çšãããŠãã補åã«å¯èœãªéãæé«ã®ã»ãã¥ãªã㣠ãªãã·ã§ã³ãæäŸããããã«ãªãœãŒã¹ãæ倧éã«æŽ»çšããããšã§ãã NSA ã®ç 究ããã°ã©ã ã®ç®æšã¯ãããŸããŸãªè»¢éã¡ã«ããºã ãéããŠãœãããŠã§ã¢éçºã³ãã¥ããã£ãšå ±æã§ããæè¡çé²æ©ãéçºããããšã§ãã NSA ã¯ãç¹å®ã®ãœãããŠã§ã¢è£œåãããžãã¹ ã¢ãã«ãæšå¥šãŸãã¯æšé²ãããã®ã§ã¯ãããŸããã ããããNSA ã¯å®å šä¿éãæšé²ããŠããŸãã - NSA 㯠Linux ããµããŒãããŠããŸãã?
äžã§è¿°ã¹ãããã«ãNSA ã¯ç¹å®ã®ãœãããŠã§ã¢è£œåããã©ãããã©ãŒã ãæšå¥šããã宣äŒããããããã®ã§ã¯ãããŸããã NSA ã¯ã»ãã¥ãªãã£ã®åäžã«ã®ã¿è²¢ç®ããŸãã SELinux ãªãã¡ã¬ã³ã¹å®è£ ã§å®èšŒããã Flask ã¢ãŒããã¯ãã£ã¯ãSolarisãFreeBSDãDarwin ãªã©ã®ä»ã®ããã€ãã®ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã«ç§»æ€ãããXen ãã€ããŒãã€ã¶ãŒã«ç§»æ€ãããX Window SystemãGConfãD-BUSãPostgreSQL ãªã©ã®ã¢ããªã±ãŒã·ã§ã³ã«é©çšãããŠããŸãã ã Flask ã¢ãŒããã¯ãã£ã®æŠå¿µã¯ãå¹ åºãã·ã¹ãã ãç°å¢ã«åºãé©çšã§ããŸãã
åå
- Linux ã³ãã¥ããã£ãšã©ã®ããã«äº€æµããäºå®ã§ãã?
æã ã¯æã£ãŠããNSA.gov ã® Web ããŒãžã®ã»ãã ãã»ãã¥ãªãã£ã匷åããã Linux æ å ±ãå ¬éããäž»ãªæ¹æ³ãšããŠæ©èœããŸãã ã»ãã¥ãªãã£ã匷åããã Linux ã«èå³ãããå Žåã¯ãéçºè ã¡ãŒãªã³ã° ãªã¹ãã«åå ãããœãŒã¹ ã³ãŒãã衚瀺ãããã£ãŒããã㯠(ãŸãã¯ã³ãŒã) ãæäŸããããšããå§ãããŸãã éçºè ã¡ãŒãªã³ã° ãªã¹ãã«åå ããã«ã¯ã次ãåç §ããŠãã ãããSELinux éçºè ã¡ãŒãªã³ã° ãªã¹ã ããŒãž . - 誰ãå©ããŠãããã§ããããïŒ
SELinux ã¯çŸåšããªãŒãã³ãœãŒã¹ Linux ãœãããŠã§ã¢ ã³ãã¥ããã£ã«ãã£ãŠç¶æããã³æ¹åãããŠããŸãã - NSAã¯è¿œè·¡èª¿æ»ã«è³éãæäŸããŠããŸãã?
NSAã¯çŸåšããããªãåãçµã¿ã®ææ¡ãæ€èšããŠããªãã - ã©ã®ãããªçš®é¡ã®ãµããŒããå©çšå¯èœã§ãã?
ã¡ãŒãªã³ã°ãªã¹ããéããŠåé¡ã解決ããã€ããã§ã [ã¡ãŒã«ä¿è·], ãã ããç¹å®ã®ãµã€ãã«é¢ãããã¹ãŠã®è³ªåã«ã¯ãçãã§ããŸããã - 誰ãå©ããŠãããã®ïŒ 圌ãã¯äœãããã®ã§ããããïŒ
ã»ãã¥ãªãã£ã匷åããã Linux ãããã¿ã€ãã¯ãNSA ã NAI LabsãSecure Computing Corporation (SCC)ãããã³ MITRE Corporation ã®ç 究ããŒãããŒãšååããŠéçºããŸããã æåã®å ¬éãªãªãŒã¹ã®åŸãããã«å€ãã®è³æãç¶ããŸãããåå è ãªã¹ããèŠã . - 詳现ã¯ã©ãããã°ããããŸãã?
ãã²åœç€Ÿã® Web ããŒãžã«ã¢ã¯ã»ã¹ããããã¥ã¡ã³ããéå»ã®ç 究è«æãèªã¿ãã¡ãŒãªã³ã° ãªã¹ãã«åå ããããšããå§ãããŸãã [ã¡ãŒã«ä¿è·]
翻蚳ã¯åœ¹ã«ç«ã¡ãŸããã? ã³ã¡ã³ããæžããŠãã ããïŒ
åºæïŒ habr.com