security review of Performance spec

"Cihula, Joseph" <[email protected]> Thu, 30 Sep 2004 11:50:59 -0700
Newsgroups gmane.linux.kernel.carrier-grade
Message-ID <CA95C29D57188841ABB072EA7357C00D06199516@orsmsx402.amr.corp.intel.com>
I've looked at the Performance spec from a security point of view and
have the following comments/questions:

Have the real-time performance changes been tested on a system using an
LSM such as SELinux?  It is important that LSM security support not have
to be traded off with performance (requirements or minimums), since the
sacrifice of either would be undesirable.  That is not to say that using
an LSM will have no performance impact but rather that the performance
requirements/minimums should not be so strict as to preclude the use of
a reasonable and well-written LSM.

PRF.33.5 Prioritized protocol processing:
	The requirement should include security-related "guarantees"
that this mechanism will not be abuseable by a user process to starve
more critical processes of network packets.

PRF.8.0 Page flushing:
	The description states that this "may have security
implications".  If so (I wasn't able to determine any by reading on
fsync()) then these should be explicitly stated or, better yet,
mitigated.

Joseph Cihula
(Linux) Software Security Architect
Intel Corp.

*** These opinions are not necessarily those of my employer ***

_______________________________________________
cgl_discussion mailing list
[email protected]
http://lists.osdl.org/mailman/listinfo/cgl_discussion