A founding goal of
Tresys is to
innovate new
technology to solve
today’s IT security
challenges. We have
an extensive R&D
program focused on
achieving that goal,
with a particular
emphasis on SELinux.
For many years
Tresys has shared
the results of our
research with the
open source
community in order
to make SELinux
easier to use.
Certifiable Linux
Integration Platform
(CLIP)
Tresys has
worked with US
Government agencies
to provide a Linux
platform configured
to support
applications
targeting the
Director of Central
Intelligence
Directive 6/3
“Protecting
Sensitive
Compartmented
Information within
Information Systems”
(DCID 6/3)
Protection Level 4
(PL4) requirements.
The complete CLIP
suite includes
operating system
configuration
guidance, mapping of
OS capabilities
against security
guidance (DCID 6/3
and National
Institute of
Standards (NIST)
Special Publication
800-53 “Recommended
Security Controls
for Federal
Information Systems”
High Impact
requirements) and
Certification and
Accreditation (C&A)
artifacts.
SETools Policy
Analysis Suite
SETools is a suite
of open source tools
that allow a policy
developer or tester
to perform detailed
analysis and
debugging of an
SELinux policy.
Tresys has been
contributing these
tools to the open
source community for
many years, and they
are included with
most Linux
distributions that
support SELinux.
Reference Policy
The Reference
Policy project makes
it easier to
maintain and apply
baseline security
policy for Security
Enhanced Linux
(SELinux). The
project makes
SELinux easier to
use for a broader
set of secure
applications, as
well as making
SELinux policies
compatible with new,
emerging policy
management
technology.
Loadable Policy
Modules
The loadable
module project is an
open source effort
that is part of a
long-term strategy
to improve the
SELinux policy
management
infrastructure, and
to support planned
SELinux management
tools.
SELinux Policy IDE
(SLIDE)
Tresys is
building an open
source tool to aid
in the development
and customization of
SELinux policies for
applications,
services, and other
secure Linux based
solutions. The
project includes an
integrated
development
environment based on
the Reference Policy
project that makes
policy development
easier.
CDS Framework IDE
Tresys is
developing and open
source IDE that
provides an
easy-to-use language
specifically
designed for cross
domain solution
developers. This IDE
allows CDS
developers to use
the power of SELinux
without requiring
detailed
understanding of the
policy language.
Conditional Policy
Extension
This extension
to SELinux allows
developers to create
policy options that
are enabled and
disabled by system
administrators at
runtime, allowing
the kernel to
enforce conditional
policies.
Policy Management
Server
The SELinux
policy server
project, along with
loadable modules, is
part of a long-term
strategy to improve
the policy
management
infrastructure. The
policy server
provides two core
operating system
services: remote
management, and
granular security
for the SELinux
policy itself.