ContentRegister/LoginSchedule Paper Presentations Tutorials BOFS/Meetings Sponsors ContactsInformationRelatedVenueTravel FAQ ArchivesProceedingsPhotos 2003 2002 2001 2000 1999 Home |
Demands, Solutions, and Improvements for Linux Filesystem SecurityMichael Austin Halcrow (linuxsymposium.org@halcrow.us)Securing file resources under Linux is a team effort. Process credentials, filesystem attributes, PAM, LSMs, and other portions of the Linux distribution must all work in concert to provide a comprehensive solution to file integrity and confidentiality while maintaining requisite functionality and transparency. As evidenced by the inclusion of cryptographic loopback support in the 2.6 kernel, demand for filesystem encryption is growing in the community. Loop-AES, CFS, TCFS, EncFS, Cryptfs, NCryptfs, and others serve as examples of currently existing cryptographic filesystems, and each has its own set of strengths and drawbacks. In this paper, I present a survey of filesystem security options in Linux, with examples of how to utilize several of the solutions that currently exist. I also address several areas of potential improvement in Linux filesystem security. |