Chapter 9. Analyzing Policy Behavior
Although SELinux policies enforce wanted behavior on a system, knowing how a policy will act up front is necessary for administrators. It assists in the execution of assessments as well as root-cause analysis activities. In this chapter, we will:
Learn how to query the SELinux policy in depth
Use a multitude of tools to query process transitions
Be able to analyze information flows
We'll end the chapter with a few smaller analysis tools, including one that shows the differences between two policy files.