LSM: Linux Security Module
https://www.kernel.org/doc/html/latest/admin-guide/LSM/index.html
- By label: SELinux, Smack;
- By path: AppArmor, TOMOYO, Landlock;
- LoadPin: 确保所有固件、内核模块来自同一文件系统;
- Yama:限制 ptrace;
- SafeSetID:限制 setid 切换 uid 和 gid;
- Integrity Policy Enforcement (IPE):基于数据完整性(数字签名)的安全策略;
沙箱工具
- Low-level tools
- AppArmor
- Container
- gVisor
- KataContainers
- High-level tools