<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Linux Kernel Security (SELinux vs AppArmor vs Grsecurity)</title> <atom:link href="http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html/feed" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html</link> <description>This is a Linux sys admin journal by Vivek about sys admin work, Linux tips &#38; tricks, hacks, news and more.</description> <lastBuildDate>Fri, 10 Feb 2012 20:37:43 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: batou</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-173052</link> <dc:creator>batou</dc:creator> <pubDate>Thu, 04 Aug 2011 20:28:13 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-173052</guid> <description>Bad, bad article - things are messed up.  AppArmor (as now used in Ubuntu say 10.04, 10.10) is the easiest tool - but least powerful, and GrSecurity is the very strong but probably harder to start with tool - for geek admins, not for random Ubuntu user that just starts with linux.. ;)
Also what others said - AppArmor is path based and SELinux is notable for labelling, actually SELinux probably IS the most common example of needing labeling...</description> <content:encoded><![CDATA[<p>Bad, bad article &#8211; things are messed up.  AppArmor (as now used in Ubuntu say 10.04, 10.10) is the easiest tool &#8211; but least powerful, and GrSecurity is the very strong but probably harder to start with tool &#8211; for geek admins, not for random Ubuntu user that just starts with linux.. ;)<br
/> Also what others said &#8211; AppArmor is path based and SELinux is notable for labelling, actually SELinux probably IS the most common example of needing labeling&#8230;</p> ]]></content:encoded> </item> <item><title>By: Dave Keays</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-172629</link> <dc:creator>Dave Keays</dc:creator> <pubDate>Thu, 21 Jul 2011 06:18:40 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-172629</guid> <description>&quot;Pathname based system does not require labelling or relabelling filesystem&quot;
I&#039;ve only lightly played with SELinux and your comparison chart really threw a curve at me. Until I read the comments I was wondering what was wrong with my installation.</description> <content:encoded><![CDATA[<p>&#8220;Pathname based system does not require labelling or relabelling filesystem&#8221;<br
/> I&#8217;ve only lightly played with SELinux and your comparison chart really threw a curve at me. Until I read the comments I was wondering what was wrong with my installation.</p> ]]></content:encoded> </item> <item><title>By: Wannabe</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-171687</link> <dc:creator>Wannabe</dc:creator> <pubDate>Wed, 01 Jun 2011 13:48:58 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-171687</guid> <description>Thanks for the great comparison.  I&#039;d also like to agree with the previous posters that in the table the last row (&quot;Feature&quot;) has the SELinux and AppArmor fields flipped.  Otherwise, nice work!</description> <content:encoded><![CDATA[<p>Thanks for the great comparison.  I&#8217;d also like to agree with the previous posters that in the table the last row (&#8220;Feature&#8221;) has the SELinux and AppArmor fields flipped.  Otherwise, nice work!</p> ]]></content:encoded> </item> <item><title>By: Doofy</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-168148</link> <dc:creator>Doofy</dc:creator> <pubDate>Sat, 08 Jan 2011 12:50:28 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-168148</guid> <description>Hi,
Please revise the last row in your comparison table.
I think apparmor is path based and selinux is lable based.</description> <content:encoded><![CDATA[<p>Hi,<br
/> Please revise the last row in your comparison table.<br
/> I think apparmor is path based and selinux is lable based.</p> ]]></content:encoded> </item> <item><title>By: Georgi Kolev</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-161410</link> <dc:creator>Georgi Kolev</dc:creator> <pubDate>Fri, 19 Nov 2010 11:54:00 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-161410</guid> <description>Nice article :)
p.s.: Slackware dosn&#039;t include SELinux (or AppArmor / grsecurity ).</description> <content:encoded><![CDATA[<p>Nice article :)<br
/> p.s.: Slackware dosn&#8217;t include SELinux (or AppArmor / grsecurity ).</p> ]]></content:encoded> </item> <item><title>By: Andrea</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-159291</link> <dc:creator>Andrea</dc:creator> <pubDate>Thu, 02 Sep 2010 09:32:56 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-159291</guid> <description>there is an error in the Feature table:
SELinux attaches labels to all files, processes and objects and not AppArmor...</description> <content:encoded><![CDATA[<p>there is an error in the Feature table:</p><p>SELinux attaches labels to all files, processes and objects and not AppArmor&#8230;</p> ]]></content:encoded> </item> <item><title>By: szymon_g</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-155207</link> <dc:creator>szymon_g</dc:creator> <pubDate>Wed, 21 Apr 2010 00:09:42 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-155207</guid> <description>nice site, but I would add some information:
1. Apparmor- this project is dead. Novell fired AA developers in Oct 2007. OpenSUSE is prepared for shipping with SELinux (although it doesn&#039;t have workable policies, unlike Fedora)- base programs and libraries are installed, common userland apps are patched etc.
2. Grsecurity (incl. PaX) is much more than &#039;traditional&#039; MAC - it also offers memory protection, ASLR etc
3. Where is TOMOYO? it was included in 2.6.30, it offers better security (if configured properly) than AA (but less than SELinux); its really nice for use (offers &#039;learning mode&#039;, human-readable policies, works fine with updates of system /libraries etc/</description> <content:encoded><![CDATA[<p>nice site, but I would add some information:<br
/> 1. Apparmor- this project is dead. Novell fired AA developers in Oct 2007. OpenSUSE is prepared for shipping with SELinux (although it doesn&#8217;t have workable policies, unlike Fedora)- base programs and libraries are installed, common userland apps are patched etc.<br
/> 2. Grsecurity (incl. PaX) is much more than &#8216;traditional&#8217; MAC &#8211; it also offers memory protection, ASLR etc<br
/> 3. Where is TOMOYO? it was included in 2.6.30, it offers better security (if configured properly) than AA (but less than SELinux); its really nice for use (offers &#8216;learning mode&#8217;, human-readable policies, works fine with updates of system /libraries etc/</p> ]]></content:encoded> </item> <item><title>By: anon</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-154061</link> <dc:creator>anon</dc:creator> <pubDate>Wed, 03 Mar 2010 05:09:22 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-154061</guid> <description>selinux has 7% + overhead... some benchmarks on some tasks like network intensive show overhead of 16%.  Google &quot;selinux overhead&quot; for plenty of links.
@miker,
yep, he mixed up the entries in his table, but apparently doesn&#039;t care.</description> <content:encoded><![CDATA[<p>selinux has 7% + overhead&#8230; some benchmarks on some tasks like network intensive show overhead of 16%.  Google &#8220;selinux overhead&#8221; for plenty of links.</p><p>@miker,<br
/> yep, he mixed up the entries in his table, but apparently doesn&#8217;t care.</p> ]]></content:encoded> </item> <item><title>By: duck</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-153778</link> <dc:creator>duck</dc:creator> <pubDate>Thu, 18 Feb 2010 18:15:24 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-153778</guid> <description>Oh and http://www.grsecurity.net/grsecurity-slide.ppt says there&#039;s minimal performance impact with Grsecurity&#039;s NX but other features can show an impact of 3%-20%. And I&#039;m sure SELinux is even worse...</description> <content:encoded><![CDATA[<p>Oh and <a
href="http://www.grsecurity.net/grsecurity-slide.ppt" rel="nofollow">http://www.grsecurity.net/grsecurity-slide.ppt</a> says there&#8217;s minimal performance impact with Grsecurity&#8217;s NX but other features can show an impact of 3%-20%. And I&#8217;m sure SELinux is even worse&#8230;</p> ]]></content:encoded> </item> <item><title>By: duck</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-153776</link> <dc:creator>duck</dc:creator> <pubDate>Thu, 18 Feb 2010 17:32:11 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-153776</guid> <description>I&#039;m not sure about that &quot;performance impact: none&quot;. For example, according to Novell&#039;s official FAQ, Apparmor&#039;s performance impact should be around 2%...</description> <content:encoded><![CDATA[<p>I&#8217;m not sure about that &#8220;performance impact: none&#8221;. For example, according to Novell&#8217;s official FAQ, Apparmor&#8217;s performance impact should be around 2%&#8230;</p> ]]></content:encoded> </item> <item><title>By: Miker</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-150370</link> <dc:creator>Miker</dc:creator> <pubDate>Wed, 26 Aug 2009 19:11:43 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-150370</guid> <description>I think you have a mix-up in the summary table on the features line.  Selinux uses labels and Apparmor uses paths correct?</description> <content:encoded><![CDATA[<p>I think you have a mix-up in the summary table on the features line.  Selinux uses labels and Apparmor uses paths correct?</p> ]]></content:encoded> </item> <item><title>By: Matt Summers</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-148815</link> <dc:creator>Matt Summers</dc:creator> <pubDate>Wed, 03 Jun 2009 13:40:37 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-148815</guid> <description>Nice article. I wanted to mention that the PAX/GrSecurity patch set goes far beyond MAC in terms of hardening your system. The stack smashing protection is huge. At Gentoo we are working on a stable implementation with gcc-4.3. Results are really solid so far, a lot of progress has been made. Gentoo&#039;s Hardened Project has some pretty good docs related to Pax/GrSec as well as SELinux, however we do not currently work with AppArmor. For any edge device or mission critical system with untrusted users Pax/GrSec is without a doubt the weapon of choice. Feel free to jump on Freenode IRC channel #gentoo-hardened if you have any questions.</description> <content:encoded><![CDATA[<p>Nice article. I wanted to mention that the PAX/GrSecurity patch set goes far beyond MAC in terms of hardening your system. The stack smashing protection is huge. At Gentoo we are working on a stable implementation with gcc-4.3. Results are really solid so far, a lot of progress has been made. Gentoo&#8217;s Hardened Project has some pretty good docs related to Pax/GrSec as well as SELinux, however we do not currently work with AppArmor. For any edge device or mission critical system with untrusted users Pax/GrSec is without a doubt the weapon of choice. Feel free to jump on Freenode IRC channel #gentoo-hardened if you have any questions.</p> ]]></content:encoded> </item> <item><title>By: Vivek Gite</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-148735</link> <dc:creator>Vivek Gite</dc:creator> <pubDate>Wed, 27 May 2009 23:52:17 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-148735</guid> <description>@Alexander,
Thanks for pointing out new info.</description> <content:encoded><![CDATA[<p>@Alexander,</p><p>Thanks for pointing out new info.</p> ]]></content:encoded> </item> <item><title>By: Alexander Slesarev</title><link>http://www.cyberciti.biz/tips/selinux-vs-apparmor-vs-grsecurity.html#comment-148734</link> <dc:creator>Alexander Slesarev</dc:creator> <pubDate>Wed, 27 May 2009 23:31:41 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/?p=4903#comment-148734</guid> <description>Sorry, but I want to notice that the future of the AppArmor project is not so bright. &lt;a href=&quot;http://news.cnet.com/8301-13580_3-9796140-39.html&quot; rel=&quot;nofollow&quot;&gt;Novell lie off AppArmor programmers&lt;/a&gt;, including Crispin Cowan (AppArmor&#039;s founder and leader). Crispin is now working in the &lt;a href=&quot;http://blogs.msdn.com/michael_howard/archive/2008/01/17/crispin-cowan-joins-the-windows-security-team.aspx&quot; rel=&quot;nofollow&quot;&gt;Microsoft&lt;/a&gt; company.
Other AppArmor&#039;s key developers (Steve Beattie and Dominic Reynolds) wanted to organize an AppArmor consulting company called Mercenary Linux. But there are no any links to this company, and the declared site is providing an adult content now.
&lt;a href=&quot;http://developer.novell.com/wiki/index.php/Novell_AppArmor&quot; rel=&quot;nofollow&quot;&gt;Last releases of AppArmor&lt;/a&gt; was about a year ago, and there are not any seen movements in this direction now.</description> <content:encoded><![CDATA[<p>Sorry, but I want to notice that the future of the AppArmor project is not so bright. <a
href="http://news.cnet.com/8301-13580_3-9796140-39.html" rel="nofollow">Novell lie off AppArmor programmers</a>, including Crispin Cowan (AppArmor&#8217;s founder and leader). Crispin is now working in the <a
href="http://blogs.msdn.com/michael_howard/archive/2008/01/17/crispin-cowan-joins-the-windows-security-team.aspx" rel="nofollow">Microsoft</a> company.</p><p>Other AppArmor&#8217;s key developers (Steve Beattie and Dominic Reynolds) wanted to organize an AppArmor consulting company called Mercenary Linux. But there are no any links to this company, and the declared site is providing an adult content now.</p><p><a
href="http://developer.novell.com/wiki/index.php/Novell_AppArmor" rel="nofollow">Last releases of AppArmor</a> was about a year ago, and there are not any seen movements in this direction now.</p> ]]></content:encoded> </item> </channel> </rss>
