<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://kernsec.org/wiki/index.php?action=history&amp;feed=atom&amp;title=Linux_Security_Summit_2012%2FAbstracts%2FHanda</id>
	<title>Linux Security Summit 2012/Abstracts/Handa - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://kernsec.org/wiki/index.php?action=history&amp;feed=atom&amp;title=Linux_Security_Summit_2012%2FAbstracts%2FHanda"/>
	<link rel="alternate" type="text/html" href="http://kernsec.org/wiki/index.php?title=Linux_Security_Summit_2012/Abstracts/Handa&amp;action=history"/>
	<updated>2026-04-20T17:29:05Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.36.1</generator>
	<entry>
		<id>http://kernsec.org/wiki/index.php?title=Linux_Security_Summit_2012/Abstracts/Handa&amp;diff=3338&amp;oldid=prev</id>
		<title>JamesMorris: /* Presenter */</title>
		<link rel="alternate" type="text/html" href="http://kernsec.org/wiki/index.php?title=Linux_Security_Summit_2012/Abstracts/Handa&amp;diff=3338&amp;oldid=prev"/>
		<updated>2012-06-27T14:03:25Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Presenter&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 14:03, 27 June 2012&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l5&quot;&gt;Line 5:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 5:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Presenter ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Presenter ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Tetsuo Handa, NTT &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Data Intellilink&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Tetsuo Handa, NTT&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Abstract ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Abstract ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>JamesMorris</name></author>
	</entry>
	<entry>
		<id>http://kernsec.org/wiki/index.php?title=Linux_Security_Summit_2012/Abstracts/Handa&amp;diff=3306&amp;oldid=prev</id>
		<title>JamesMorris: New page: == Title ==  CaitSith - A New Type of Rule Based In-kernel Access Control  == Presenter ==  Tetsuo Handa, NTT Data Intellilink  == Abstract ==  There had been various attempts for enforcin...</title>
		<link rel="alternate" type="text/html" href="http://kernsec.org/wiki/index.php?title=Linux_Security_Summit_2012/Abstracts/Handa&amp;diff=3306&amp;oldid=prev"/>
		<updated>2012-06-27T04:22:56Z</updated>

		<summary type="html">&lt;p&gt;New page: == Title ==  CaitSith - A New Type of Rule Based In-kernel Access Control  == Presenter ==  Tetsuo Handa, NTT Data Intellilink  == Abstract ==  There had been various attempts for enforcin...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Title ==&lt;br /&gt;
&lt;br /&gt;
CaitSith - A New Type of Rule Based In-kernel Access Control&lt;br /&gt;
&lt;br /&gt;
== Presenter ==&lt;br /&gt;
&lt;br /&gt;
Tetsuo Handa, NTT Data Intellilink&lt;br /&gt;
&lt;br /&gt;
== Abstract ==&lt;br /&gt;
&lt;br /&gt;
There had been various attempts for enforcing rule based access control in the&lt;br /&gt;
Linux kernel. Many distributions nowadays enable some of in-tree LSM modules.&lt;br /&gt;
However, many people are still disabling these modules because these modules&lt;br /&gt;
are too complicated for them to use. Although white-listing approach is popular&lt;br /&gt;
among security experts than black-listing approach, black-listing approach&lt;br /&gt;
seems to be popular among those who are not security experts. In this&lt;br /&gt;
presentation, CaitSith, a new type of rule based access control that mixed&lt;br /&gt;
capability model and ACL model, is proposed. The rules in CaitSith are similar&lt;br /&gt;
to network firewall and allow black-listing approach.&lt;br /&gt;
&lt;br /&gt;
Expected audiences are Linux users who are disabling in-tree LSM modules, are&lt;br /&gt;
seeking for more simplified form of in-kernel access control, or are developing&lt;br /&gt;
LSM modules. Audiences will know why CaitSith was developed and basic usage of&lt;br /&gt;
CaitSith.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Tetsuo Handa is the main author of TOMOYO (one of in-tree LSM modules), AKARI&lt;br /&gt;
(loadable kernel module version of TOMOYO) and CaitSith. He had been involved&lt;br /&gt;
in the area of in-kernel access control from April 2003 to March 2012 at NTT&lt;br /&gt;
DATA CORPORATION, Japan. He had talks/BoFs at several Linux related&lt;br /&gt;
international conferences and PacSec 2008.&lt;/div&gt;</summary>
		<author><name>JamesMorris</name></author>
	</entry>
</feed>