[CentOS] [OT][Practices] The Case for RBAC/MAC

Sat Nov 19 01:15:08 UTC 2005
Lamar Owen <lowen at pari.edu>

On Friday 18 November 2005 09:55, Brian T. Brunner wrote:
> Who, pray tell, is my attacker?

The Windows box that just got infected from a floppy disk, CD, or other media, 
and it is inside your firewall (if you have one).  Of course, if all your 
systems are embedded, or have no network connections, then there is no 
attacker in the traditional sense.

However, SELinux can provide more protection than that, perhaps even 
preventing a bug in the code that's running from blowing away critical files, 
for a possible (even if not probable) example.
-- 
Lamar Owen
Director of Information Technology
Pisgah Astronomical Research Institute
1 PARI Drive
Rosman, NC  28772
(828)862-5554
www.pari.edu