{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T01:46:48Z","timestamp":1787017608736,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":26,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,5,8]],"date-time":"2023-05-08T00:00:00Z","timestamp":1683504000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,5,8]]},"DOI":"10.1145\/3578357.3589454","type":"proceedings-article","created":{"date-parts":[[2023,5,4]],"date-time":"2023-05-04T15:30:12Z","timestamp":1683214212000},"page":"1-7","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["A Comparative Analysis of Linux Mandatory Access Control Policy Enforcement Mechanisms"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-3790-8052","authenticated-orcid":false,"given":"Brennon","family":"Brimhall","sequence":"first","affiliation":[{"name":"Johns Hopkins University, Baltimore, MD, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-3690-2046","authenticated-orcid":false,"given":"Justin","family":"Garrard","sequence":"additional","affiliation":[{"name":"Engineering for Professionals, Johns Hopkins University, Baltimore, Maryland, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-7667-0555","authenticated-orcid":false,"given":"Christopher","family":"De La Garza","sequence":"additional","affiliation":[{"name":"Engineering for Professionals, Johns Hopkins University, Baltimore, Maryland, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5500-4450","authenticated-orcid":false,"given":"Joel","family":"Coffman","sequence":"additional","affiliation":[{"name":"Engineering for Professionals, Johns Hopkins University, Baltimore, Maryland, USA"},{"name":"Department of Computer and Cyber Sciences, United States Air Force Academy, USAF Academy, Colorado, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,5,8]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Mach: A New Kernel Foundation For UNIX Development. In USENIX Summer Conference. USENIX.","author":"Accetta Mike","year":"1986","unstructured":"Mike Accetta , Robert Baron , William Bolosky , David Golub , Richard Rashid , Avadis Tevanian , and Michael Young . 1986 . Mach: A New Kernel Foundation For UNIX Development. In USENIX Summer Conference. USENIX. Mike Accetta, Robert Baron, William Bolosky, David Golub, Richard Rashid, Avadis Tevanian, and Michael Young. 1986. Mach: A New Kernel Foundation For UNIX Development. In USENIX Summer Conference. USENIX."},{"key":"e_1_3_2_1_2_1","volume-title":"Proceedings of the 2009 NDSS Symposium (NDSS 2009","author":"Chen Hong","year":"2009","unstructured":"Hong Chen , Ninghui Li , and Ziqing Mao . 2009 . Analyzing and Comparing the Protection Quality of Security Enhanced Operating Systems . In Proceedings of the 2009 NDSS Symposium (NDSS 2009 ). (Feb. 2009). Hong Chen, Ninghui Li, and Ziqing Mao. 2009. Analyzing and Comparing the Protection Quality of Security Enhanced Operating Systems. In Proceedings of the 2009 NDSS Symposium (NDSS 2009). (Feb. 2009)."},{"key":"e_1_3_2_1_3_1","volume-title":"KRSI - the other BPF security module. (Dec","author":"Corbet Jonathan","year":"2019","unstructured":"Jonathan Corbet . 2019. KRSI - the other BPF security module. (Dec . 2019 ). https:\/\/lwn.net\/Articles\/808048\/. Jonathan Corbet. 2019. KRSI - the other BPF security module. (Dec. 2019). https:\/\/lwn.net\/Articles\/808048\/."},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the 14th Systems Administration Conference (LISA 2000","author":"Cowan Crispin","year":"2000","unstructured":"Crispin Cowan , Steve Beattie , Greg Kroah-Hartman , Calton Pu , Perry Wagle , and Virgil Gligor . 2000 . SubDomain: Parsimonious Server Security . In Proceedings of the 14th Systems Administration Conference (LISA 2000 ). The USENIX Association , (Dec. 2000). https:\/\/www.usenix.org\/legacy\/event\/lisa2000\/full_papers\/cowan\/cowan.pdf. Crispin Cowan, Steve Beattie, Greg Kroah-Hartman, Calton Pu, Perry Wagle, and Virgil Gligor. 2000. SubDomain: Parsimonious Server Security. In Proceedings of the 14th Systems Administration Conference (LISA 2000). The USENIX Association, (Dec. 2000). https:\/\/www.usenix.org\/legacy\/event\/lisa2000\/full_papers\/cowan\/cowan.pdf."},{"key":"e_1_3_2_1_5_1","volume-title":"A seccomp overview. (Sept","author":"Edge Jake","year":"2015","unstructured":"Jake Edge . 2015. A seccomp overview. (Sept . 2015 ). https:\/\/lwn.net\/Articles\/656307\/. Jake Edge. 2015. A seccomp overview. (Sept. 2015). https:\/\/lwn.net\/Articles\/656307\/."},{"key":"e_1_3_2_1_6_1","volume-title":"Security Applications of Extended BPF Under the Linux Kernel. (Apr","author":"Findlay William","year":"2020","unstructured":"William Findlay . 2020. Security Applications of Extended BPF Under the Linux Kernel. (Apr . 2020 ). https:\/\/www.cisl.carleton.ca\/-will\/written\/findlay20bpfsec.pdf. William Findlay. 2020. Security Applications of Extended BPF Under the Linux Kernel. (Apr. 2020). https:\/\/www.cisl.carleton.ca\/-will\/written\/findlay20bpfsec.pdf."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3411495.3421358"},{"key":"e_1_3_2_1_8_1","volume-title":"A thorough introduction to eBPF. (Dec","author":"Fleming Matt","year":"2017","unstructured":"Matt Fleming . 2017. A thorough introduction to eBPF. (Dec . 2017 ). https:\/\/lwn.net\/Articles\/740157\/. Matt Fleming. 2017. A thorough introduction to eBPF. (Dec. 2017). https:\/\/lwn.net\/Articles\/740157\/."},{"key":"e_1_3_2_1_9_1","volume-title":"Security Module Infrastructure for Linux and macOS. (Apr","author":"Freyensee J.","year":"2020","unstructured":"J. Freyensee . 2020. Security Module Infrastructure for Linux and macOS. (Apr . 2020 ). https:\/\/medium.com\/macos-is-not-linux-and-other-nix-reflections\/security-module-infrastructure-for-linux-and-macos-cf677fa520b7. J. Freyensee. 2020. Security Module Infrastructure for Linux and macOS. (Apr. 2020). https:\/\/medium.com\/macos-is-not-linux-and-other-nix-reflections\/security-module-infrastructure-for-linux-and-macos-cf677fa520b7."},{"key":"e_1_3_2_1_10_1","volume-title":"SELinux User's and Administrator's Guide. (Aug","author":"Jahoda Mirek","year":"2019","unstructured":"Mirek Jahoda , Barbora An\u010dincov\u00e1 , Ioanna Gkioka , and Tom\u00e1\u0161 \u010capek . 2019. SELinux User's and Administrator's Guide. (Aug . 2019 ). https:\/\/access.redhat.com\/documentation\/en-us\/red_hat_enterprise_linux\/7\/html-single\/selinux_users_and_administrators_guide\/index. Mirek Jahoda, Barbora An\u010dincov\u00e1, Ioanna Gkioka, and Tom\u00e1\u0161 \u010capek. 2019. SELinux User's and Administrator's Guide. (Aug. 2019). https:\/\/access.redhat.com\/documentation\/en-us\/red_hat_enterprise_linux\/7\/html-single\/selinux_users_and_administrators_guide\/index."},{"key":"e_1_3_2_1_11_1","volume-title":"Watson","author":"Kamp Poul-Henning","year":"2000","unstructured":"Poul-Henning Kamp and Robert N. M . Watson . 2000 . Jails : Confining the omnipotent root. https:\/\/papers.freebsd.org\/2000\/phk-jails.files\/sane2000-jail.pdf. Poul-Henning Kamp and Robert N. M. Watson. 2000. Jails: Confining the omnipotent root. https:\/\/papers.freebsd.org\/2000\/phk-jails.files\/sane2000-jail.pdf."},{"key":"e_1_3_2_1_12_1","volume-title":"Linux Security Module Usage. (June","author":"Community Kernel Development","year":"2022","unstructured":"Kernel Development Community . 2022. Linux Security Module Usage. (June 2022 ). https:\/\/docs.kernel.org\/admin-guide\/LSM\/index.html. Kernel Development Community. 2022. Linux Security Module Usage. (June 2022). https:\/\/docs.kernel.org\/admin-guide\/LSM\/index.html."},{"key":"e_1_3_2_1_13_1","volume-title":"2001 USENIX Annual Technical Conference (USENIX ATC 01)","author":"Loscocco Peter","year":"2001","unstructured":"Peter Loscocco and Stephen Smalley . 2001 . Integrating Flexible Support for Security Policies into the Linux Operating System . In 2001 USENIX Annual Technical Conference (USENIX ATC 01) . USENIX Association, Boston, MA , (June 2001). https:\/\/www.usenix.org\/conference\/2001-usenix-annual-technical-conference\/integrating-flexible-support-security-policies. Peter Loscocco and Stephen Smalley. 2001. Integrating Flexible Support for Security Policies into the Linux Operating System. In 2001 USENIX Annual Technical Conference (USENIX ATC 01). USENIX Association, Boston, MA, (June 2001). https:\/\/www.usenix.org\/conference\/2001-usenix-annual-technical-conference\/integrating-flexible-support-security-policies."},{"key":"e_1_3_2_1_14_1","volume-title":"The Design and Implementation of the FreeBSD Operating System","author":"McKusick M.K.","year":"1968","unstructured":"M.K. McKusick , G.V. Neville-Neil , and R.N.M. Watson . 2014. The Design and Implementation of the FreeBSD Operating System . Addison Wesley . isbn: 978-032 1968 975. M.K. McKusick, G.V. Neville-Neil, and R.N.M. Watson. 2014. The Design and Implementation of the FreeBSD Operating System. Addison Wesley. isbn: 978-0321968975."},{"key":"e_1_3_2_1_15_1","volume-title":"Solaris Zones: Operating System Support for Consolidating Commercial Workloads. In 18th Large Installation System Administration Conference (LISA 04)","author":"Price Daniel","year":"2004","unstructured":"Daniel Price and Andrew Tucker . 2004 . Solaris Zones: Operating System Support for Consolidating Commercial Workloads. In 18th Large Installation System Administration Conference (LISA 04) . USENIX Association, Atlanta, GA , (Nov. 2004). https:\/\/www.usenix.org\/legacy\/publications\/library\/proceedings\/lisa04\/tech\/price.html. Daniel Price and Andrew Tucker. 2004. Solaris Zones: Operating System Support for Consolidating Commercial Workloads. In 18th Large Installation System Administration Conference (LISA 04). USENIX Association, Atlanta, GA, (Nov. 2004). https:\/\/www.usenix.org\/legacy\/publications\/library\/proceedings\/lisa04\/tech\/price.html."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/361011.361061"},{"key":"e_1_3_2_1_17_1","volume-title":"Inside the Linux Security Module (LSM). (July","author":"Salve Vandana","year":"2020","unstructured":"Vandana Salve . 2020. Inside the Linux Security Module (LSM). (July 2020 ). https:\/\/elinux.org\/images\/0\/0a\/ELC_Inside_LSM.pdf. Vandana Salve. 2020. Inside the Linux Security Module (LSM). (July 2020). https:\/\/elinux.org\/images\/0\/0a\/ELC_Inside_LSM.pdf."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2019599.2019604"},{"key":"e_1_3_2_1_19_1","volume-title":"Using SELinux: Writing a Custom SELinux Policy. (Aug","author":"Customer Content Services Red Hat","year":"2022","unstructured":"Red Hat Customer Content Services . 2022. Using SELinux: Writing a Custom SELinux Policy. (Aug . 2022 ). https:\/\/access.redhat.com\/documentation\/en-us\/red_hat_enterprise_linux\/8\/html\/using_selinux\/writing-a-custom-selinux-policy_using-selinux. Red Hat Customer Content Services. 2022. Using SELinux: Writing a Custom SELinux Policy. (Aug. 2022). https:\/\/access.redhat.com\/documentation\/en-us\/red_hat_enterprise_linux\/8\/html\/using_selinux\/writing-a-custom-selinux-policy_using-selinux."},{"key":"e_1_3_2_1_20_1","volume-title":"Kernel Runtime Security Instrumentation. (Sept","author":"Singh KP","year":"2019","unstructured":"KP Singh . 2019. Kernel Runtime Security Instrumentation. (Sept . 2019 ). https:\/\/lwn.net\/Articles\/798918\/. KP Singh. 2019. Kernel Runtime Security Instrumentation. (Sept. 2019). https:\/\/lwn.net\/Articles\/798918\/."},{"key":"e_1_3_2_1_21_1","volume-title":"Configuring the SELinux Policy. (Feb","author":"Smalley Stephen","year":"2005","unstructured":"Stephen Smalley . 2005. Configuring the SELinux Policy. (Feb . 2005 ). https:\/\/www.nsa.gov\/portals\/75\/images\/resources\/everyone\/digital-media-center\/publications\/research-papers\/configuring-selinux-policy-report.pdf. Stephen Smalley. 2005. Configuring the SELinux Policy. (Feb. 2005). https:\/\/www.nsa.gov\/portals\/75\/images\/resources\/everyone\/digital-media-center\/publications\/research-papers\/configuring-selinux-policy-report.pdf."},{"key":"e_1_3_2_1_22_1","volume-title":"Implementing SELinux as a Linux Security Module. (Feb","author":"Smalley Stephen","year":"2006","unstructured":"Stephen Smalley , Chris Vance , and Wayne Salamon . 2006. Implementing SELinux as a Linux Security Module. (Feb . 2006 ). https:\/\/www.nsa.gov\/portals\/75\/documents\/resources\/everyone\/digital-media-center\/publications\/research-papers\/implementing-selinux-as-linux-security-module-report.pdf. Stephen Smalley, Chris Vance, and Wayne Salamon. 2006. Implementing SELinux as a Linux Security Module. (Feb. 2006). https:\/\/www.nsa.gov\/portals\/75\/documents\/resources\/everyone\/digital-media-center\/publications\/research-papers\/implementing-selinux-as-linux-security-module-report.pdf."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1093\/biomet\/34.1-2.28"},{"key":"e_1_3_2_1_24_1","volume-title":"SANS GIAC Certifications, (Dec.","author":"Wilson Billy","year":"2020","unstructured":"Billy Wilson . 2020 . Mitigating Attacks on a Supercomputer with KRSI . SANS GIAC Certifications, (Dec. 2020). Billy Wilson. 2020. Mitigating Attacks on a Supercomputer with KRSI. SANS GIAC Certifications, (Dec. 2020)."},{"key":"e_1_3_2_1_25_1","volume-title":"In: Ottawa Linux Symposium, Citeseer.","author":"Wright Chris","year":"2002","unstructured":"Chris Wright , Crispin Cowan , James Morris , Stephen Smalley , and Greg Kroah-hartman. 2002 . G.: Linux security module framework . In In: Ottawa Linux Symposium, Citeseer. Chris Wright, Crispin Cowan, James Morris, Stephen Smalley, and Greg Kroah-hartman. 2002. G.: Linux security module framework. In In: Ottawa Linux Symposium, Citeseer."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453078"}],"event":{"name":"EUROSEC '23: 16th European Workshop on System Security","location":"Rome Italy","acronym":"EUROSEC '23","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 16th European Workshop on System Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3578357.3589454","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T12:46:51Z","timestamp":1750164411000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3578357.3589454"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,8]]},"references-count":26,"alternative-id":["10.1145\/3578357.3589454","10.1145\/3578357"],"URL":"https:\/\/doi.org\/10.1145\/3578357.3589454","relation":{},"subject":[],"published":{"date-parts":[[2023,5,8]]},"assertion":[{"value":"2023-05-08","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}