Binary Policy with IMA and AppArmor

No ratings

Presented at LinuxSecuritySummit 2019 by

Google operates one of the largest fleet of developer machines, supporting a wide range of user workflows and expectations. While techniques such as social voting of binaries for whitelisting on other OSes have been successful, Corp Security has taken novel approaches on Linux workstations for providence based policy. Over the past year Eric’s worked to build features into AppArmor for targeting IMA signatures, enabling restrictions of executables that don’t originate from Google’s centralized package repositories. This talk will dive into the technical aspects of Google’s binary signing and operational challenges rolling out restrictive policies at scale.