<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Engineering Research Group &#187; Trusted Computing</title>
	<atom:link href="http://imsciences.edu.pk/serg/category/trusted-computing/feed/" rel="self" type="application/rss+xml" />
	<link>http://imsciences.edu.pk/serg</link>
	<description>Security Engineering Research Group</description>
	<lastBuildDate>Thu, 02 Sep 2010 07:48:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Video Lectures Available</title>
		<link>http://imsciences.edu.pk/serg/2009/05/video-lectures-available/</link>
		<comments>http://imsciences.edu.pk/serg/2009/05/video-lectures-available/#comments</comments>
		<pubDate>Mon, 18 May 2009 13:49:32 +0000</pubDate>
		<dc:creator>recluze</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Trusted Computing]]></category>
		<category><![CDATA[Tutorials]]></category>

		<guid isPermaLink="false">http://imsciences.edu.pk/serg/?p=240</guid>
		<description><![CDATA[Video Lectures related to the project Dynamic Behavioral Attestation for Mobile Platforms are now available. You can see the (constantly updated) list of uploaded video lectures here.
]]></description>
			<content:encoded><![CDATA[<p>Video Lectures related to the project Dynamic Behavioral Attestation for Mobile Platforms are now available. You can see the (constantly updated) list of uploaded video lectures <a href="http://imsciences.edu.pk/serg/projects/dbamp/resources/">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://imsciences.edu.pk/serg/2009/05/video-lectures-available/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>SELinux on FreeRunner</title>
		<link>http://imsciences.edu.pk/serg/2009/04/selinux-on-freerunner/</link>
		<comments>http://imsciences.edu.pk/serg/2009/04/selinux-on-freerunner/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 09:47:27 +0000</pubDate>
		<dc:creator>shazkhan</dc:creator>
				<category><![CDATA[Achievements]]></category>
		<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[SELinux]]></category>
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://imsciences.edu.pk/serg/?p=238</guid>
		<description><![CDATA[We have successfully built NSA SELinux for OpenMoko FreeRunner with support for policy 19-23 using kernel-2.6.24. Most of it was cross compilation and understanding of the kernel and userspace infrastructure of SELinux.
The policy is now being developed further to suite our solutions in permissive mode. Check out http://www.facebook.com/group.php?gid=72016920562
]]></description>
			<content:encoded><![CDATA[<p>We have successfully built NSA SELinux for OpenMoko FreeRunner with support for policy 19-23 using kernel-2.6.24. Most of it was cross compilation and understanding of the kernel and userspace infrastructure of SELinux.</p>
<p>The policy is now being developed further to suite our solutions in permissive mode. Check out http://www.facebook.com/group.php?gid=72016920562</p>
]]></content:encoded>
			<wfw:commentRss>http://imsciences.edu.pk/serg/2009/04/selinux-on-freerunner/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Trust 2009 Paper</title>
		<link>http://imsciences.edu.pk/serg/2009/01/trust-2009-paper/</link>
		<comments>http://imsciences.edu.pk/serg/2009/01/trust-2009-paper/#comments</comments>
		<pubDate>Thu, 08 Jan 2009 10:50:22 +0000</pubDate>
		<dc:creator>recluze</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://imsciences.edu.pk/serg/?p=234</guid>
		<description><![CDATA[The contribution by SERG has been accepted for the technical strand of the International Conference on Technical and Socio-economic Aspects of Trusted Computing (Trust 2009). So, SERG will probably be represented by one of its members at the conference. More on this later after the registration process opens up (and is completed).
]]></description>
			<content:encoded><![CDATA[<p>The contribution by SERG has been accepted for the technical strand of the International Conference on Technical and Socio-economic Aspects of Trusted Computing (Trust 2009). So, SERG will probably be represented by one of its members at the conference. More on this later after the registration process opens up (and is completed).</p>
]]></content:encoded>
			<wfw:commentRss>http://imsciences.edu.pk/serg/2009/01/trust-2009-paper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Applications that Enforce System Security&#8221;</title>
		<link>http://imsciences.edu.pk/serg/2008/06/applications-that-enforce-system-security/</link>
		<comments>http://imsciences.edu.pk/serg/2008/06/applications-that-enforce-system-security/#comments</comments>
		<pubDate>Tue, 17 Jun 2008 09:11:30 +0000</pubDate>
		<dc:creator>recluze</dc:creator>
				<category><![CDATA[Ideas]]></category>
		<category><![CDATA[SELinux]]></category>
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://imsciences.edu.pk/serg/?p=199</guid>
		<description><![CDATA[[These are comments to the paper titled, "From Trusted to Secure: Building and Executing Applications That Enforce System Security" available at USENIX ATC'07.]
The paper deals with the issue of differences between security enforcement on the operating system level and within applications. It describes a mechanism through which security labels of a MAC mechanism from the [...]]]></description>
			<content:encoded><![CDATA[<p>[These are comments to the paper titled, "From Trusted to Secure: Building and Executing Applications That Enforce System Security" available at <a href="http://www.usenix.org/events/usenix07/tech/hicks.html">USENIX ATC'07</a>.]</p>
<p>The paper deals with the issue of differences between security enforcement on the operating system level and within applications. It describes a mechanism through which security labels of a MAC mechanism from the OS can be communicated to the application; the application provides assurance that it enforces the security policies within its logic; the output of information from the application is also communicated to the OS MAC mechanism to ensure that these outputs get the correct labels.</p>
<p>Things to notice:</p>
<ul>
<li>The architecture relies on security typed languages (Jif to be specific) to ensure that no illegal information flow can occur within the application</li>
<li>The architecture provides an interface through which OS policies can be communicated to and from the application</li>
<li>It provides a mechanism which provides assurance that the policies of the OS are being implemented correctly and</li>
<li>It uses a high level policy to describe &#8220;declassifiers&#8221; &#8212; interfaces which are allowed to move information from high level of security to a lower level.</li>
</ul>
<p>I found the last point of particular importance because it explained to me exactly what <a href="http://portal.acm.org/citation.cfm?id=1133063">PRIMA</a> meant by &#8216;interfaces which convert data of low integrity to high integrity&#8217;.</p>
<p>Another important point to note is that the information flow analysis to and from the application is not static (as in Jif &#8211; which uses compile time checks only, as far as I know) but dynamic in that the lattice of principals is created at runtime (meaning that mappings of labels to and from the OS would occur at runtime thus depending on the OS policy at runtime).</p>
<p>The developer does not have to know these mappings either. They are defined in a separate high-level policy so that they can be defined by the system administrator on the target machine.</p>
<p>The concept of mappings is particularly clarified through Figure 6 and the fifth paragraph in Section 4.3. The policy within the appplication allows pub -&gt; siic -&gt; sec. pub is mapped to security level s0 of the OS and sec to s1. Information can thus from from s0 to s1 (but only if this is allowed by the OS!) The Jif Runtime takes care of this sort of information flow.</p>
<p>Future directions of my interest:</p>
<ol>
<li>policy compliance analysis between application policy and OS policy.</li>
<li>declassifier generalization (although the authors themselves have pointed out a few works in this direction).</li>
<li>issues of attestation of the architecture. (I believe this is not so straight forward due to the inter-linkages between different modules of the architecture but then, attestation is never easy anyway. <img src='http://imsciences.edu.pk/serg/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  )</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://imsciences.edu.pk/serg/2008/06/applications-that-enforce-system-security/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>ARM links with Trusted Logic for secure mobiles, set tops</title>
		<link>http://imsciences.edu.pk/serg/2008/01/arm-links-with-trusted-logic-for-secure-mobiles-set-tops/</link>
		<comments>http://imsciences.edu.pk/serg/2008/01/arm-links-with-trusted-logic-for-secure-mobiles-set-tops/#comments</comments>
		<pubDate>Tue, 29 Jan 2008 18:47:24 +0000</pubDate>
		<dc:creator>clickforamin</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://securityengineering.wordpress.com/2008/01/29/arm-links-with-trusted-logic-for-secure-mobiles-set-tops/</guid>
		<description><![CDATA[
ARM Ltd. has teamed with Trusted Logic to develop secure software for mobile handsets and set-top boxes that will combine the microprocessor core maker&#8217;s TrustZone technology with optimized security software from Trusted Logic&#8230;..
Embedded.com &#8211; ARM links with Trusted Logic for secure mobiles, set tops:

amin.


]]></description>
			<content:encoded><![CDATA[<p>
ARM Ltd. has teamed with Trusted Logic to develop secure software for mobile handsets and set-top boxes that will combine the microprocessor core maker&#8217;s TrustZone technology with optimized security software from Trusted Logic&#8230;..</p>
<p><a href="http://www.embedded.com/news/internetappliance/23900682?_requestid=263711">Embedded.com &#8211; ARM links with Trusted Logic for secure mobiles, set tops</a>:</p>
<p>
amin.</p>
<blockquote><p>
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://imsciences.edu.pk/serg/2008/01/arm-links-with-trusted-logic-for-secure-mobiles-set-tops/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Needs of network for MAC</title>
		<link>http://imsciences.edu.pk/serg/2007/08/needs-of-network-for-mac/</link>
		<comments>http://imsciences.edu.pk/serg/2007/08/needs-of-network-for-mac/#comments</comments>
		<pubDate>Sat, 25 Aug 2007 22:18:04 +0000</pubDate>
		<dc:creator>shazkhan</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[SELinux]]></category>
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://securityengineering.wordpress.com/2007/08/25/needs-of-network-for-mac/</guid>
		<description><![CDATA[After the comparison of trendy MAC enhancements, I have been figuring out the general needs of a network for MAC. We have three places where MAC can and is enforced:

In Application: Where flow control of application is controled by labeling the data of the application. Current research is limited to MLS becuase its simple. And [...]]]></description>
			<content:encoded><![CDATA[<p>After the comparison of trendy MAC enhancements, I have been figuring out the general needs of a network for MAC. We have three places where MAC can and is enforced:</p>
<ol>
<li>In Application: Where flow control of application is controled by labeling the data of the application. Current research is limited to MLS becuase its simple. And because the security type languages are not mature enough to handle the granularity. I have seen two framworks at this level, which make use of these languages. One of them has been partially integerated with selinux by using the application layer API to selinuxfs. I am curious why they are so interested in JAVA! There is no C extension.</li>
<li>On Application Layer: This is achieved for applications that do not use TCP/IP directly. They use RPCs so the common network controls cannot handle properly. The reason is that port to application mapping is done by portmapper daemon. Thus the rpc headers carry the security contexts. Such applications are NFS and NIS.</li>
<li>At TCP/IP Layer: Here the ports are labeled for the associated applications on both sides. I a hostile environment this would not prove useful so encryption would also be required. This is achieved by IPSEC associations being labeled. I am not fully satisfied by the mechanisms at this level because at one extreme we have lack of security and on the other hand manageability issues.</li>
</ol>
<p>LDAP is on the todo list but nothing is currently being done about it upto my knowledge. The todo list also wants more granularity and API at TCP/IP layer.</p>
<p>Policy distribution being a great issue has no solid solutions yet. The only possibility to till now is a tranlation server, which would provide an equivalence mehanism for internode security contexts. But this is has been left as an idea and no progress is being made. IPSEC associations were provided only for subjects but currently they are working for providing object support but the work is hidden yet. They are thinking for CIFS support as well. Ephimeral ports can be handled with standard SELinux API for applications.</p>
<p>The biggest problem with distributed policy is the type enforcement, which is part of the security model/context. Leaving it out would be a solution but will affect greatly because code bindings will be lost, which will result in loss of integrity control. The context has three main models. User identity, role and TE. If one is lost it will affect the others because they are tied together to help each other. I am figuring out how much affect will be made. At the same time integrity can be measured with IMA and alike. I would like comments on what you ppl think about the differences in the integrity model of TE and IMA.</p>
<p>If anyone can come up with other ideas of network needs plz brainstorm so I figure out the requirements. There are others which I have&#8217;nt mentioned because they are trusted applications by SELinux. I find a gap over here because trusting applications is not a good idea. Information flows can work here. More on this when I get a solid insight on them.</p>
<p>What do you guys think should be my next target. Amin is sorting out to integerate his study with all this. So give ideas of possibilities. Any of you who thinks their work can have relevance plz share your findings so that we can be more useful to each other.</p>
]]></content:encoded>
			<wfw:commentRss>http://imsciences.edu.pk/serg/2007/08/needs-of-network-for-mac/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>TPM HACKS-Controversial Security Paper Nixed From Black Hat!</title>
		<link>http://imsciences.edu.pk/serg/2007/08/tpm-hacks-controversial-security-paper-nixed-from-black-hat/</link>
		<comments>http://imsciences.edu.pk/serg/2007/08/tpm-hacks-controversial-security-paper-nixed-from-black-hat/#comments</comments>
		<pubDate>Tue, 07 Aug 2007 22:21:17 +0000</pubDate>
		<dc:creator>clickforamin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://securityengineering.wordpress.com/2007/08/07/tpm-hacks-controversial-security-paper-nixed-from-black-hat/</guid>
		<description><![CDATA[ 			coondoggie writes us with a link to the Network World site, as he tends to do. Today he offers an article discussing the cancellation of a presentation which would have undermined chip-based security on PCs. Scheduled during the Black Hat USA 2007 event, the event&#8217;s briefing promised to break the Trusted Computing Group&#8217;s module, [...]]]></description>
			<content:encoded><![CDATA[<div class="intro"> 			<a href="http://networkworld.com/" rel="nofollow">coondoggie</a> writes us with a link to the Network World site, as he tends to do. Today he offers an article discussing the cancellation of a presentation which would have <a href="http://www.networkworld.com/news/2007/062707-black-hat.html">undermined chip-based security on PCs</a>. Scheduled during the Black Hat USA 2007 event, the event&#8217;s briefing promised to break the Trusted Computing Group&#8217;s module, as well as Vista&#8217;s Bitlocker. Live demos were to be included. The presenters pulled the event, and have no interest in discussing the subject any more. <i>&#8220;[Presenters Nitin and Vipin Kumar's] promised exploit would be a chink in the armor of hardware-based system integrity that [trusted platform module] (TPM) is designed to ensure. TPM is also a key component of Trusted Computing Group&#8217;s architecture for network access control (NAC). TPM would create a unique value or hash of all the steps of a computer&#8217;s boot sequence that would represent the particular state of that machine, according to Steve Hanna, co-chair of TCG&#8217;s NAC effort.&#8221;</p>
<p>amin.<br />
</i> 		</div>
]]></content:encoded>
			<wfw:commentRss>http://imsciences.edu.pk/serg/2007/08/tpm-hacks-controversial-security-paper-nixed-from-black-hat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IMA as a standalone service</title>
		<link>http://imsciences.edu.pk/serg/2007/07/ima-as-a-standalone-service/</link>
		<comments>http://imsciences.edu.pk/serg/2007/07/ima-as-a-standalone-service/#comments</comments>
		<pubDate>Sun, 22 Jul 2007 09:59:19 +0000</pubDate>
		<dc:creator>shazkhan</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://securityengineering.wordpress.com/2007/07/22/ima-as-a-standalone-service/</guid>
		<description><![CDATA[The following paras are from the linux mailing list which is a mail sent by ibm ima team. They are working out this userspace ima thingy. I am still not satisfied. Mr. TAT can you plz verify it? I can email u the patches and the related mails as well. 
This is a request for comments for a subset of the [...]]]></description>
			<content:encoded><![CDATA[<p>The following paras are from the linux mailing list which is a mail sent by ibm ima team. They are working out this userspace ima thingy. I am still not satisfied. Mr. TAT can you plz verify it? I can email u the patches and the related mails as well. </p>
<blockquote><p><em>This is a request for comments for a subset of the original integrity<br />
patches. By submitting this subset of the original patches, we hope to<br />
simplify its review and ultimately ease its inclusion into the kernel.<br />
For this reason, neither EVM nor SLIM are included in this patchset.<br />
This patchset contains: Linux Integrity Module(LIM), Integrity<br />
Measurement Architecture (<span class="st"><font>IMA</font></span>), and patches to the TPM driver. The LIM<br />
patch defines 3 integrity API calls, 7 integrity hooks, placement of<br />
the hooks, and a dummy integrity service provider. There are very minor<br />
changes from the previous release.  The <span class="st"><font>IMA</font></span> patch is now an independent<br />
integrity service provider, which provides support for a subset of the<br />
integrity API calls.</p>
<p>IBAC, a sample LSM module, which helps clarify the interaction between<br />
LSM and LIM modules, will be posted separately to the LSM mailing list.<br />
In addition, we are working on an SELinux integrity patch to take<br />
advantage of the integrity services, in a similar way to the IBAC<br />
example.</p>
<p>Patch 1/3 integrity: Linux Integrity Module (LIM)<br />
Patch 2/3 integrity: <span class="st"><font>IMA</font></span> as a stand alone integrity service provider<br />
Patch 3/3 integrity: TPM internal kernel interface</p>
<p>Mimi Zohar<br />
Dave Safford</em><a href="http://securityengineering.wordpress.com/2007/07/20/future-directions-and-some-extra-stuff/#comments"></a></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://imsciences.edu.pk/serg/2007/07/ima-as-a-standalone-service/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>TPM Manager for Linux released!</title>
		<link>http://imsciences.edu.pk/serg/2007/07/tpm-manager-for-linux-released/</link>
		<comments>http://imsciences.edu.pk/serg/2007/07/tpm-manager-for-linux-released/#comments</comments>
		<pubDate>Fri, 06 Jul 2007 10:33:14 +0000</pubDate>
		<dc:creator>clickforamin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://securityengineering.wordpress.com/2007/07/06/tpm-manager-for-linux-released/</guid>
		<description><![CDATA[Ruhr-University Bochum and Sirrix AG have developed an open source application providing an easy to use graphical user interface to manage and configure a Trusted Platform Module (TPM).
The TPM Manager can be used on PC systems equipped with a TPM that is supported by the Linux kernel. Users of such systems can now easily check [...]]]></description>
			<content:encoded><![CDATA[<p>Ruhr-University Bochum and Sirrix AG have developed an open source application providing an easy to use graphical user interface to manage and configure a Trusted Platform Module (TPM).</p>
<p>The TPM Manager can be used on PC systems equipped with a TPM that is supported by the Linux kernel. Users of such systems can now easily check the capabilities of their TPM, read out public keys and certificates, or change the TPM settings like, e.g., disable or activate it.</p>
<p>The TPM Manager is currently available for Linux only, but should be easily portable to other operating systems providing a TSS API. The source code of the TPM Manager is available on SourceForge at [1] and licensed under GPL. We (Ruhr-University Bochum and Sirrix AG ) appreciate feedback from users who like to give it a try. Users will also find help and support on the Trusted Computing Forum at [2].</p>
<p>[1] http://sourceforge.net/projects/tpmmanager/<br />
[2] http://forum.emscb.org</p>
<p>amin.</p>
]]></content:encoded>
			<wfw:commentRss>http://imsciences.edu.pk/serg/2007/07/tpm-manager-for-linux-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Slim, EVM and TPM (3.2.0)</title>
		<link>http://imsciences.edu.pk/serg/2007/06/slim-evm-and-tpm-320/</link>
		<comments>http://imsciences.edu.pk/serg/2007/06/slim-evm-and-tpm-320/#comments</comments>
		<pubDate>Sat, 02 Jun 2007 11:47:34 +0000</pubDate>
		<dc:creator>shazkhan</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Trusted Computing]]></category>

		<guid isPermaLink="false">http://securityengineering.wordpress.com/2007/06/02/109/</guid>
		<description><![CDATA[Follow this link  for a simple idea. Further it has a link to ibm research page. This link metions an old study but this page will be updated.
Let me know what you ppl think of it. It is a more updated approach than IMA. And it is a loadable userspace module! Mr. MMA will like [...]]]></description>
			<content:encoded><![CDATA[<p><font size="2">Follow <a href="http://lwn.net/Articles/160126/">this link</a>  for a simple idea. Further it has a link to ibm research page. This link metions an old study but this page will be updated.</font></p>
<p><font size="2">Let me know what you ppl think of it. It is a more updated approach than IMA. And it is a loadable userspace module! Mr. MMA will like it.</font></p>
<p><font size="2">Sir Mr. MMA I am waiting for your coments regarding IPSec article by Joshua.</font></p>
]]></content:encoded>
			<wfw:commentRss>http://imsciences.edu.pk/serg/2007/06/slim-evm-and-tpm-320/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>
