Smack

E724149

Smack (Simplified Mandatory Access Control Kernel) is a Linux kernel security module that implements a simple mandatory access control system to confine processes and protect data.

All labels observed (2)

Label Occurrences
Smack canonical 2
SMACK 1

How this entity was disambiguated

Statements (48)

Predicate Object
instanceOf Linux security module ⓘ
mandatory access control system ⓘ
abbreviation Smack ⓘ
accessControlGranularity subject and object labels ⓘ
accessDecisionBasis label rules ⓘ
category Linux kernel security ⓘ
computer security software ⓘ
comparedWith AppArmor ⓘ
SELinux ⓘ
configurationInterface /etc/smack/accesses policy files ⓘ
file system extended attributes ⓘ
kernel configuration options ⓘ
designedBy Casey Schaufler ⓘ
designedFor low administrative overhead ⓘ
simplicity of configuration ⓘ
designGoal easier policy management than SELinux ⓘ
smaller policy set than SELinux ⓘ
documentation Linux kernel Documentation/security/Smack.txt ⓘ
enforcementLocation Linux kernel ⓘ
fullName Simplified Mandatory Access Control Kernel ⓘ
implements label-based access control ⓘ
introducedIn Linux kernel 2.6 series ⓘ
linked to: Linux kernel
kernelComponent Linux kernel ⓘ
license GNU General Public License ⓘ
mainlineStatus merged into mainline Linux kernel ⓘ
operatingSystem Linux ⓘ
partOf Linux Security Modules framework ⓘ
policyType discretionary label rules defined by administrator ⓘ
purpose confining processes ⓘ
protecting data ⓘ
securityModel mandatory access control ⓘ
securityProperty confinement of processes ⓘ
data isolation ⓘ
policy-based access control ⓘ
supports IPv4 network labeling ⓘ
IPv6 network labeling ⓘ
NFS with Smack labels ⓘ
access control for IPC mechanisms ⓘ
access control for files ⓘ
access control for sockets ⓘ
file system object labeling ⓘ
inter-process communication control ⓘ
network access control ⓘ
network packet labeling ⓘ
process labeling ⓘ
useCase appliance-like systems ⓘ
embedded systems ⓘ
systems requiring simple MAC policies ⓘ

How these facts were elicited

Referenced by (3)

Full triples — surface form annotated when it differs from this entity's canonical label.

Linux kernel hardening → usesMechanism → SMACK ⓘ
linked to: Smack
LSM API → usedBy → Smack ⓘ