Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

Lecture 4 FreeBSD Security + FreeBSD Jails + MAC Security Framework


Published on

Lecture 4 FreeBSD Security + FreeBSD Jails + MAC Security Framework

Published in: Education, Technology
  • Be the first to comment

  • Be the first to like this

Lecture 4 FreeBSD Security + FreeBSD Jails + MAC Security Framework

  1. 1. Mohammed Farragmfarrag@freebsd.org<br />
  2. 2. Security Types<br />
  3. 3. Encryption and Decryption.<br />Symmetric and Asymmetric.<br />Security Topics<br />
  4. 4. FreeBSD Security Categories<br />
  5. 5. UFS:<br />implement special filesystem flags on files.<br />flags enforce the same behavior for all users.<br />kernel is responsible for enforcing these controls, depending on your kernel securelevel.<br />Filesystem Protections<br />
  6. 6. UFS2: <br />use Access Control Lists producing fine-grained control over permissions.<br />Different users can be given different sets of permissions without relying on traditional Unix groups. <br />
  7. 7. Turn off the flag<br /> Specifying 0 in place of a flag name will turn off all the flags on a file. It's an inelegant little shortcut, but it works. For example, chflags 0foo will turn off all the flags on the file foo.<br />
  8. 8. Use –o option of ls command<br />Example: /var/log<br />-rw------- 1 root wheel sappnd 1862 Sep 30 22:39 auth.log <br />-rw------- 1 root wheel sappnd 38374 Sep 30 22:45 cron<br />-rw------- 1 root wheel nodump 3157 Sep 30 03:06<br />-rw-r--r-- 1 root wheel sappnd 28056 Sep 30 22:39 lastlog<br />-rw-r--r-- 1 root wheel - 0 Jun 4 21:57 lpd-errs <br />-rw-r----- 1 root wheel sappnd 2160 Sep 30 03:06 maillog<br />-rw-r--r-- 1 root wheel sappnd 15547 Sep 30 22:47 messages <br />-rw-r----- 1 root mail sappnd 628 Sep 30 03:06 <br />-rw-r----- 1 root mail schg 3455 Sep 29 22:00 <br />-rw-r----- 1 root mail schg 5543 Jun 4 21:57<br />View active flags on a file<br />
  9. 9. schg, is derived from "system change," it is universally referred to as the "immutable" flag. When the system immutable flag is set on a file, nothing can modify any part of it. Its metadata (modification times, permissions, owner, group, and so on) cannot be changed, nor can its contents. It cannot be renamed, unlinked (i.e., deleted), or moved, either. <br />Only root can unset at zero kernel security level.<br />System immutable flag (schg)<br />
  10. 10. The user immutable flag is a kinder, gentler immutable flag that is not affected by the kernel securelevel. <br />Users can set and unset this on their own files and directories, just as root can. <br />Unlike the system immutable flag, this one can be unset at any time. <br />In order to be able to set this flag, you must be either the file's owner or root. <br />A user with write access via Unix groups or ACLs, for example, still cannot set this flag.<br />User immutable flag (uchg)<br />
  11. 11. Normally all files in a filesystem are backed up when the dump(8) program runs. The nodump flag tells the backup system not to include the given file in the dumps.<br />To tell dump to honor the nodump flag, specify -h on the dump command line. <br />If you want files to be omitted from backups entirely (i.e., not even included on full dumps), then you need to specify -h 0 on the command line.<br />Nodump flag (nodump)<br />
  12. 12. The append-only flag prevents files from being modified, much like the immutable flag, with one exception: data can be appended at the end of the file. The archetypal use of the append-only flag is for logfiles on secured servers or perhaps for root's .history file to help catch unwary hackers (see "Candidates for append-only," later in this chapter).<br />System append-only flag (sappnd)<br />
  13. 13. The user append-only flag performs exactly as the system append-only flag described above. The only difference is that this flag can be unset by both the owner and root at any time, regardless of the kernel securelevel.<br />User append-only flag (uappnd)<br />
  14. 14. This flag is a little weaker than the schg flag. It simply prevents the deletion of a file. It is arguably most useful in its "user" version, uunlnk. <br />It does not prevent truncation of the file or modification of its contents, its permissions, or any other aspect. It merely prevents the file from being removed.<br />Like other "system" flags, it can only be set by root, and it cannot be unset when the kernel security level is greater than 0. <br />This flag exists only in FreeBSD<br />System no unlink flag (sunlnk)<br />
  15. 15. This flag allows a user to indicate that a file may not be deleted, regardless of the actual Unix permissions on its parent directory. Normally, if a user has permissions (through user, group, or ACLs) on the parent directory, she can delete any file in the directory—even files she does not own.<br />That's because, in Unix filesystems such as UFS, the permission for deleting a file is a function of modifying the directory, not the file itself.<br />User no unlink flag (uunlnk)<br />
  16. 16. Opaque flags are used on directories or files that are involved in unionfs mounts. Union mounts allow one directory or filesystem to be mounted over the top of another directory while retaining visibility into the underlying directory. Thus, when you look in the top-level directory, you see the union of the two directories. A file that exists in one place but not the other (XOR) will be visible. If there are files or directories of the same name in both places, the "uppermost" one is the one that is accessible.<br />Opaque flag (opaque)<br />
  17. 17. When a directory is marked opaque with the opaque flag, it only shows files that actually exist in its level. That is, it makes the union mount act like a regular mount; files in the corresponding directory of a lower layer will be invisible.<br />Opaque flag (opaque) – cont’d<br />
  18. 18. The find command understands flags if you give it the -flags argument. <br />For instance, this command finds all files that have the uunlnk flag set in user paco's home directory: <br /> find /home/paco -flags +uunlnk -print. <br />File Flags Searching<br />
  19. 19. /etc/fstab file <br />Tagging the superblock directly<br />Enable ACLs<br />
  20. 20. /etc/fstab<br />Enable ACL Option for /home directory<br />
  21. 21. Preferable.<br />Can be used in two ways<br /><ul><li> Single User Mode.
  22. 22. unmount idle filesystemwith the following steps
  23. 23. umount it.
  24. 24. run tunefs -a /home.</li></ul>ACLs in the superblock<br />
  25. 25. % setfacl -b book.pdf # Erase any existing ACLs<br /># Add ahmed’s access<br />% setfacl -m u:ahmed:rw book.pdf<br /># Nobody else gets any permission at all<br />setfacl -m o:: book.pdf<br />Setting ACLs for Files<br />File name<br />User/Group/Others<br />User/Group name<br />Access Rights<br />
  26. 26. getfacl book.pdf<br /> #file:book.pdf <br /> #owner:1001 <br /> #group:100 <br /> user::rw- user:ahmed:rw- <br /> mask::rw- <br /> other::---<br />Viewing ACLs for Files<br />
  27. 27. We can modify the kernel security architecture using Sysctl’s.<br />We have 5 levels of kernel security (-1 .. 3).<br />Enable Kernel Security:<br /><ul><li> Secure the kernel till the next boot
  28. 28. In the shell, sysctlkern.securelevel=2
  29. 29. Secure the kernel permanently.
  30. 30. In /etc/sysctl.conf, sysctlkern.securelevel=2</li></ul>Kernel<br />
  31. 31.
  32. 32. chroot<br />Jail<br />User Process Control<br />
  33. 33. The principles behind chroot are simple. <br /> A process running in a chrooted environment sees a normal filesystem, but it in fact has a virtual root directory. The goal is to prevent the process from accessing files outside its sandbox. <br />chroot<br />
  34. 34. If ntpd runs in a chrooted environment, for example, and an exploit is discovered that causes it to overwrite a file, files in the real filesystem should be protected. The daemon perceives a / directory and will write relative to that directory, but on the real filesystem, the directory is something like /var/ntpd, and the daemon cannot actually reach the real / directory.<br />
  35. 35. Jails expand this model by virtualizing not only access to the file system, but also the set of users, the networking subsystem of the FreeBSD kernel and a few other things.<br />FreeBSD Jail<br />
  36. 36. A directory subtree -- the starting point from which a jail is entered. Once inside the jail, a process is not permitted to escape outside of this subtree. <br />A hostname -- the hostname which will be used within the jail. Jails are mainly used for hosting network services, therefore having a descriptive hostname for each jail can really help the system administrator.<br />An IP address -- this will be assigned to the jail and cannot be changed in any way during the jail's life span. <br />A command -- the path name of an executable to run inside the jail. <br />Jail Characteristics<br />
  37. 37. # setenv D /here/is/the/jail<br /># mkdir -p $D <br /># cd /usr/src<br /># make buildworld<br /># make installworld DESTDIR=$D <br /># make distribution DESTDIR=$D <br /># mount -t devfsdevfs $D/dev <br />Creating Jails<br />
  38. 38. Selecting a location for a jail is the best starting point. This is where the jail will physically reside within the file system of the jail's host. <br />A good choice can be /usr/jail/jailname, where jailname is the hostname identifying the jail. <br /># mkdir -p $D <br />
  39. 39. The distribution target for make installs every needed configuration file. In simple words, it installs every installable file of /usr/src/etc/ to the /etc directory of the jail environment: $D/etc/.<br /> make distribution DESTDIR=$D<br />
  40. 40. Mounting the devfs file system inside a jail is not required. <br />It is very important to control access to devices from inside a jail, as improper settings could permit an attacker to do nasty things in the jail. Control over devfs(8) is managed through rulesets which are described in the devfs(8) and devfs.conf(5) manual pages.<br /># mount -t devfsdevfs $D/dev <br />
  41. 41. /etc/rc.conf since it will replicate the startup sequence of a real FreeBSD system. For a service jail, it depends on the service or application that will run within the jail.<br />Jail Enabling<br />
  42. 42. Jail Configuration<br />
  43. 43. From Host System<br /># /etc/rc.d/jail start www<br /># /etc/rc.d/jail stop www<br />The best way to shut down a jail is:<br /><ul><li> # sh /etc/rc.shutdown from inside the jail.
  44. 44. using the jexecutility from outside the jail.</li></ul>Jail Starting & Stopping<br />
  45. 45. Among the many third-party utilities for jail administration, one of the most complete and useful is sysutils/jailutils. It is a set of small applications that contribute to jail management. Please refer to its web page for more information.<br />Jail High-level administrative tools<br />
  46. 46. Fighting Buffer Overflows<br />Cryptography.<br />Inherent Protection<br />
  47. 47. The goal of W^X is to make a program crash if it attempts to write to an execute-only page or execute code on a write-only page. The kernel and the loader try to make sure that a program's instructions are always allocated on pages marked executable, and data (e.g., the program's stack and heap) is always allocated to pages that are writable but not executable<br />
  48. 48. maxusers<br /> make it 0 to turn control to physical RAM.<br />Increasing Maximum Values.<br />For example, kern.ipc.somaxconn.<br />Network Buffering<br />For example, net.inet.tcp.sendspace<br />Optimizations (OS Tuning)<br />
  49. 49.
  50. 50. Safety<br />Liveness.<br /> …<br />System Security Requirements<br />
  51. 51. Policy (Access Rights)<br />
  52. 52.
  53. 53. desribes how to apply the policy<br />Mechanism<br />
  54. 54. Introduction (Time-Money Overview).<br />Framework as intermediate layer between policy writers and kernel developers.<br />Framework Capabilities. <br /><ul><li> Policy Composition.
  55. 55. Decision Making.
  56. 56. Policy-Kernel Interfacing.</li></ul>MAC Framework<br />
  57. 57. Snort.<br />Snorby.<br />Intrusion Detection Common Ports<br />
  58. 58. Questions<br />
  59. 59. Thank you<br />