|
Enhancing kernel security with grsecurity |
|
|
|
Source: Linux.com - Posted by Pax Dickinson
|
Is your server as secure as it could be? Sure, you use a firewall, mandate strong passwords, and patch regularly. You even take a proactive approach by performing security audits with tools such as nmap and Nessus. Yet you may still be vulnerable to zero-day exploits and privilege escalation attacks. If these possibilities keep you awake at night, you're not alone. The sleepless folks with the grsecurity project have developed an easy-to-use set of security enhancements to help put your fears to rest.
To say that grsecurity provides many enhancements is an understatement. There are more than 30 options to choose from after installation, including:
- A role-based access control (RBAC) system that automatically generates least-privilege policies
- Change root (chroot) hardening
- /tmp race prevention
- Extensive auditing
- Address space protection with PaX
- Additional randomness in the TCP/IP stack
- Restrictions on users to view only their own processes
- Security alerts and audits that contain the IP address of the machine that caused the
event
Read this full article at Linux.com
Powered by AkoComment! |