
1
Immunizing Programs
Novell® AppArmor provides immunization technologies that protect SUSE Linux ap-
plications from the inherent vulnerabilities they possess. After installing Novell App-
Armor, setting up Novell AppArmor profiles and rebooting the computer, your system
becomes immunized because it begins to enforce the Novell AppArmor security policies.
Protecting programs with Novell AppArmor is referred to as immunizing.
Novell AppArmor sets up a collection of default application profiles to protect standard
Linux services. To protect other applications, use the Novell AppArmor tools to create
profiles for the applications that you want protected. This chapter introduces you to the
philosophy of immunizing programs. Proceed to
Chapter 3, Building Novell AppArmor
Profiles
(page 21) if you are ready to build and manage Novell AppArmor profiles.
Novell AppArmor provides streamlined access control for network services by specifying
which files each program is allowed to read, write, and execute. This ensures that each
program does what it is supposed to do and nothing else.
Novell AppArmor is host intrusion prevention, or a mandatory access control scheme,
that is optimized for servers. Previously, access control schemes were centered around
users because they were built for large timeshare systems. Alternatively, modern network
servers largely do not permit users to log in, but instead provide a variety of network
services for users, such as Web, mail, file, and print. Novell AppArmor controls the
access given to network services and other programs to prevent weaknesses from being
exploited.
Immunizing Programs
13
Summary of Contents for APPARMOR 1.2
Page 1: ...Novell AppArmor Powered by Immunix Administration Guide www novell com 1 2 09 29 2005...
Page 4: ......
Page 14: ......
Page 116: ......
Page 128: ......