Skip to main content
[ IBM Research ]
[ Find ] [ News ] [ Products ] [ Support ] [ Business solutions ] [ Inside IBM ] [ Interest groups ]

Linux Security Analysis Tools

IBM T. J. Watson Research Center
19 Skyline Drive
Hawthorne, NY 10532

Trent Jaeger , Xiaolan (Catherine) Zhang , Reiner Sailer

The Linux Security Analysis Tools project team is looking at how to improve Linux security by building analysis tools for verifying Linux kernel source properties and access control policies. Based on our initial findings, we are optimistic that such tools are useful and usable for improving our confidence in Linux security.

The Vali project uses static and runtime analyses to verify the authorization hook placement of the Linux Security Modules (LSM) framework, a kernel patch designed to enable mandatory access control enforcement for Linux.

The Gokyo project uses an extended graphical access control model to examine the role-based or type-based access control models, such as the extended Type Enforcemen access control model of the SELinux LSM module.


Project Members


Other Projects of Interest:


Vali Papers -- Vali: Norse God of Justice (and Program Verifcation, maybe)


Gokyo Papers -- Gokyo (Ri): More attainable mountain near Everest


Other Papers

Assist Legal Privacy Orders IBM IBM Research