Главная
Study mode:
on
1
SECURITY SUMMIT
2
User data
3
What is (security) sandboxing?
4
What is Landlock?
5
How to use Landlock?
6
Current access-control features: filesystem
7
Create a ruleset
8
Add rules
9
Enforce the ruleset
10
Landlock, a bit of history
11
Why no more eBPF?
12
Priorities and guiding principles
13
Unprivileged access control
14
Composed security policies
15
LSM stacking
16
Sandbox policies composition
17
User space testing
18
Kernel fuzzing with syzkaller
19
Minimum Viable Product
20
Design limitations
21
Kernel-side roadmap
Description:
Explore the intricacies of Landlock, a security sandboxing mechanism, in this 29-minute conference talk by Mickaël Salaün from Microsoft. Delve into the fundamentals of security sandboxing, understand Landlock's purpose and functionality, and learn how to implement it effectively. Discover current access-control features for filesystems, the process of creating rulesets, adding rules, and enforcing them. Gain insights into Landlock's development history, design priorities, and guiding principles, including unprivileged access control and composed security policies. Examine the concept of LSM stacking, sandbox policy composition, and the importance of user space testing and kernel fuzzing. Understand the Minimum Viable Product approach, design limitations, and get a glimpse of the kernel-side roadmap for Landlock's future development.

Deep Dive into Landlock Internals

Linux Foundation
Add to list
0:00 / 0:00