Static analysis to assist policy creation?

2015-10-20 Thread Andrew Ruef
Hello SELinux list, We’ve been thinking about creating a static (or potentially concolic) analysis and testing infrastructure that would assist in the creation of finer grained SELinux policies than audit2allow. We think that some work can be done through alias analysis and domain specific

Re: Static analysis to assist policy creation?

2015-10-20 Thread Jason Zaman
On Tue, Oct 20, 2015 at 01:17:27PM -0400, Andrew Ruef wrote: > Hello SELinux list, > > We’ve been thinking about creating a static (or potentially concolic) > analysis and testing infrastructure that would assist in the creation of > finer grained SELinux policies than audit2allow. We think