NOTE: The event will be held in Central Daylight Time (CDT), UTC -5.

View More Details for Open Source Summit + Embedded Linux Conference North America 2020
Registration Information.
Back To Schedule
Monday, June 29 • 3:20pm - 4:10pm
Inside the Linux Security Modules (LSM) - Vandana Salve, Prasme Systems

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Many of the features for securing Linux are built either in to the Linux kernel or added by the various Linux Distribution. The Linux security Module (LSM) framework provides a mechanism for the various security checks to be hooked by the new kernel.

The LSM functionality is compiled directly into the Linux kernel using the LSM framework.
The most prevalent users of LSM interface are the Mandatory access control which provides comprehensive security policy. The existing examples are SELinux, Smack, Tomoya and AppArmor. Along with the larger set of MAC extensions, other extensions can be built using the LSM framework to provide specific changes to the system operations when these tweaks are not available in the core functionality of the Linux kernel.

The Linux security module (LSM) framework provides a mechanism for the various security checks to be hooked at the various kernel subsystem. The security is attained by the LSM framework by enforcing the access policies on the system resources.

The presentation will dive deep into the LSM framework, the different hooks supported by the existing LSM modules and how to implement new LSM module for the required functionality.

avatar for Vandana Salve

Vandana Salve

Architect, Prasme systems
Vandana is a leader and expert in the field of Linux and embedded systems and has been extensively involved in kernel and system product development and management ! * Engaged with startups to build Linux embedded Systems for board support packages, device driver development and the... Read More →

Monday June 29, 2020 3:20pm - 4:10pm CDT
ELC Theater B