20.08.2015 Views

SELinux in Android Lollipop and M

lss2015_selinuxinandroidlollipopandm_smalley

lss2015_selinuxinandroidlollipopandm_smalley

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>SEL<strong>in</strong>ux</strong> <strong>in</strong> <strong>Android</strong> 5.0 <strong>Lollipop</strong>• All system services <strong>and</strong> apps are conf<strong>in</strong>ed.– Includ<strong>in</strong>g root daemons.• Only two doma<strong>in</strong>s are “unconf<strong>in</strong>ed”.– kernel <strong>and</strong> <strong>in</strong>it• Even these two doma<strong>in</strong>s are not completelyunrestricted by <strong>SEL<strong>in</strong>ux</strong>.– TCB protection goals are applied universally.– No doma<strong>in</strong>/process is all-powerful.5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!