FLASK
E724132
FLASK is a flexible, fine-grained security architecture originally developed for operating systems like SELinux to support configurable mandatory access control policies.
Statements (47)
| Predicate | Object |
|---|---|
| instanceOf |
access control architecture
ⓘ
security architecture ⓘ |
| abbreviation | FLASK ⓘ |
| appliedTo |
Linux
NERFINISHED
ⓘ
embedded systems ⓘ microkernel-based systems ⓘ |
| associatedWith | NSA research projects ⓘ |
| category |
computer security model
ⓘ
operating system security ⓘ |
| controls | interactions between subjects and objects ⓘ |
| designedBy | National Security Agency NERFINISHED ⓘ |
| designedFor | operating systems ⓘ |
| developedFor | high-assurance systems ⓘ |
| documentationType | security architecture specification ⓘ |
| enables |
centralized security policy management
ⓘ
policy changes without code changes in object managers ⓘ |
| focusesOn |
mandatory access control enforcement
ⓘ
policy configurability ⓘ policy modularity ⓘ |
| fullName | Flux Advanced Security Kernel NERFINISHED ⓘ |
| goal |
enable strong mandatory access control
ⓘ
improve system security assurance ⓘ support multiple security policies simultaneously ⓘ |
| hasComponent |
object managers
ⓘ
policy decision mechanisms ⓘ policy enforcement mechanisms ⓘ security server ⓘ |
| hasProperty |
fine-grained
ⓘ
flexible ⓘ |
| influenced |
SELinux architecture
ⓘ
other MAC frameworks ⓘ |
| originatedIn | research on secure operating systems ⓘ |
| provides |
dynamic policy configuration
ⓘ
fine-grained access decisions ⓘ label-based access control ⓘ |
| relatedTo |
Linux Security Modules framework
NERFINISHED
ⓘ
SELinux policy language ⓘ |
| separates | policy decision from policy enforcement ⓘ |
| supports |
configurable security policies
ⓘ
mandatory access control ⓘ multi-level security policies ⓘ policy flexibility ⓘ role-based access control policies ⓘ type enforcement policies ⓘ |
| usedIn | SELinux NERFINISHED ⓘ |
| uses |
security contexts
ⓘ
security labels ⓘ |
Referenced by (1)
Full triples — surface form annotated when it differs from this entity's canonical label.