SELinux: Bring World-Class Security to Any Linux Environment!SELinux by Example is the first complete, hands-on guide to using SELinux in production environments. Authored by three leading SELinux researchers and developers, it illuminates every facet of working with SELinux, from its architecture and security object model to its policy language. The book thoroughly explains SELinux sample policies- including the powerful new Reference Policy-showing how to quickly adapt them to your unique environment. It also contains a comprehensive SELinux policy language reference and covers exciting new features in Fedora Core 5 and the upcoming Red Hat Enterprise Linux version 5.· Thoroughly understand SELinux's access control and security mechanisms· Use SELinux to construct secure systems from the ground up· Gain fine-grained control over kernel resources· Write policy statements for type enforcement, roles, users, and constraints· Use optional multilevel security to enforce information classification and manage users with diverse clearances· Create conditional policies that can be changed on-the-fly· Define, manage, and maintain SELinux security policies· Develop and write new SELinux security policy modules· Leverage emerging SELinux technologies to gain even greater flexibility· Effectively administer any SELinux system
This paper describes the Gamera framework for building custom document recognition systems. This open-source system is designed to support the testand-refine development cycle: an important style for developing recognition systems that work with difficult historical documents, since the solutions are often non-obvious. This paper explains the overall architecture of the system, in addition to detailed information on recent research subprojects and their performance on real-world data.
An optical music recognition system has been completely overhauled and reformatted into a new framework called Gamera. The new open-source software is not only designed to recognize various music notations, including handwritten scores, but can be used to develop systems that can recognize many other structured documents. Gamera is intended to be used by domain experts with particular knowledge of the documents to be recognized but without strong programming skills. Gamera contains image processing and recognition tools in an easy-to-use, interactive, graphical scripting environment. Additionally, the system can be extended through a C++ and Python plugins.
A system to convert digitized sheet music into a symbolic music representation is presented. A pragmatic approach is used that conceptualizes this primarily two-dimensional structural recognition problem as a one-dimensional one. The transparency of the implementation owes a great deal to its implementation in a dynamic, object-oriented language. This system is a part of a locally developed end-to-end solution for the conversion of digitized sheet music into symbolic form.
This paper presents a new toolkit for the creation of customized structured document recognition applications by domain experts. This open-source system, called Gamera, allows a user, with particular knowledge of the documents to be recognized, to combine image processing and recognition tools in an easy-to-use, interactive, graphical scripting environment. Gamera is one of the key technology components in a proposed international project for the digitization of diverse types of humanities documents.
This paper presents Gamera, a newtoolkit for the creation of domain-specific structured documentrecognition applications by domain experts with limited programmingexperience. The goal of the Gamera system is to leverage the user’sknowledge of the target documents to create custom applicationsrather than attempting to meet the needs of diverse users with amonolithic application. The system allows a knowledgeable user tocombine image processing and recognition tools in an intuitive,interactive, graphical scripting environment based on Python. The useof Python in Gamera creates a simple yet powerful and flexible programming environment for novice programmers. Additionally, theresulting applications are suitable for a large-scale digitizationproject because they can be run in a batch-processing mode and easilyintegrated into a digitization framework. Finally, the Python modulesystem has been extended to allow the easy creation of plugins usingPython or C++.
The realtime manipulation of audio with desktop computers has become both possible and popular over the last several years. Perhaps the most important aspect that determines the suitability of a computer operating system for this application is the latency of its audio system. This paper describes the results of an experiment measuring the audio latency of several current desktop operating systems, including Microsoft Windows, Apple MacOS, and Linux.
This paper presents a new toolkit for the creation of customized structured document recognition applications by expert users. This open-source system, called Gamera, allows a user, with particular knowledge of the documents to be recognized, to combine image processing and recognition tools in an easy to use, interactive, graphical scripting environment. Additionally, the system can be extended through a C++ module system.
The Reference Policy project is an effort to restructure the NSA example policy for SELinux, which has evolved through many years of community involvement and is the basis for nearly all sample SELinux Policy in use today. The Reference Policy is rigorously structured using modularity, layering, encapsulation, and abstraction, making it simpler to maintain, modify, and use. The goal of this restructuring is to allow greater adaptation and adoption of SELinux while maintaining the knowledge gained through the years of policy evolution, while increasing our ability to validate the security properties of a given SELinux policy. 1. Motivations When expressing security goals for an application in an Security Enhanced Linux (SELinux) policy, it is impor- tant to have a strong foundation to build upon. The problem with the sample policy that evolved from the original NSA policy (1) is that the policy is difficult to understand, develop, and maintain unless you are inti- mately familiar with the SELinux enforcement mecha- nism and the policy language. In the example policy, source files have loose structure and policy modules are closely coupled. A policy writer must have detailed knowledge of most if not the entire policy in order to use it as a basis for new application policy modules. Creating third-party modules is difficult, requiring de- tailed understanding of type, role, user, attributes, etc. definitions throughout the entire policy. While most policies in use today, e.g., (2) (3), are based on the original NSA sample policy, the single largest com- plaint about SELinux is that writing policy is too diffi- cult and complex. Tresys started the Reference Policy (4) project to re- factor the community knowledge gained through evolu- tion of the NSA example policy, into a form that exhib- its many of the strengths and features of modern soft- ware engineering, thereby making the policy more maintainable, verifiable, and useable.
Building computer systems that allow the controlled transfer of data between security domains, commonly called cross-domain solutions (CDS) or guards, presents many common and some unique security challenges. In this paper, we explore lessons learned from building several CDS systems on SELinux. We explore the desired security properties of a CDS, define the role of the operating system in enforcing these security properties, and describe our experience using SELinux to fulfill the operating system role.
Expressing security architectures that meet required security goals for a system in SELinux policy language is quite difficult, particularly for those without a strong understanding of the implications of SELinux security mechanisms and object class permissions. However, SELinux policy language is an excellent base upon which to build a higher- level policy language that more directly expresses specific security architectures. We have developed one such lan- guage, CDSFramework, for implementing security policies focused on information flow applications as typically found in cross-domain solutions. This paper presents the components of this language and describes some of the issues that we faced in implementing the language and its tools.
Ichiro Fujinaga合作论文数Schulich School of Music;McGill University;Centre for Interdisciplinary Research in Music Media and Technology (CIRMMT)12