20.08.2015 Views

SELinux in Android Lollipop and M

lss2015_selinuxinandroidlollipopandm_smalley

lss2015_selinuxinandroidlollipopandm_smalley

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Policy Harden<strong>in</strong>g• Forced <strong>in</strong>it to transition doma<strong>in</strong>s on exec.– Separate doma<strong>in</strong>s added for helper programs <strong>and</strong> allservices, even oneshot services.• Locked down block device access.– Protect<strong>in</strong>g critical partitions from direct access.– Limit<strong>in</strong>g each doma<strong>in</strong> to only needed partitions.• Removed unconf<strong>in</strong>ed doma<strong>in</strong>.– Even <strong>in</strong>it <strong>and</strong> kernel no longer use it.• Many more neverallows.19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!