Wrapping Up
Buffer overflow exploits are one of the most interesting security vulnerabilities and are used in a majority of security attacks against Linux and Unix-like operating systems. DSM guards against such exploits, and it is implemented as a Linux module. DSM also provides many other features, such as transparently controlling the access in the distributed environment of Linux clustered servers.
Some notes that should be taken into consideration as well:
In Parts 1 and 2 of this article, we presented and demonstrated that mandatory access control implemented in DSM can prevent against buffer overflow exploits. The security mechanisms were implemented in different levels of the executing system. Because many existing applications are vulnerable to the buffer overflow exploits, one of our goals with DSM was to make the security transparent to the applications, so even the existing programs can be secured without any modifications. The DSM source code is provided as open source and is available for download from the DSI Web site.
This article was originally published on LinuxPlanet.
Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved
Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.