A server administrator is configuring a new web server and wants to implement a security measure that restricts the server's processes from accessing unauthorized parts of the file system or executing unauthorized system calls, even if the process is compromised. Which hardening technique is specifically designed to provide this granular control over process behavior?
- ADisabling unnecessary services
- BApplying a host-based firewall
- CImplementing Mandatory Access Control (MAC)
- DUsing strong password policies
Show answer & explanationAnswer & explanation
Correct answer: C. Implementing Mandatory Access Control (MAC)
Mandatory Access Control (MAC), often implemented using tools like SELinux or AppArmor on Linux, enforces strict security policies on processes. It defines what resources (files, ports, system calls) a process can access, regardless of the user's discretionary permissions. This directly addresses the need for 'granular control over process behavior' and restricting processes from 'unauthorized parts of the file system or executing unauthorized system calls' even if compromised.
Why the other options are wrong
- A. Disabling services reduces the attack surface but doesn't control a compromised running process's actions.
- B. A host-based firewall controls network traffic, not internal process behavior or file system access.
- D. Strong password policies protect authentication but don't prevent a compromised service from exceeding its intended scope.
Mandatory Access Control (MAC)
A security model where the operating system restricts a subject's (e.g., process) ability to access or perform any operation on an object (e.g., file) based on security labels.
- System-enforced, users cannot override these policies.
- Provides a strong defense against privilege escalation and compromised processes.
- Examples include SELinux (Linux) and AppArmor (Linux).
Memory trick: Process Control: MAC is the 'Mandatory' Guardian!