evilsocket / evilsocket/opensnitch

[Feature Request] AppArmor label operand

Open
#1,649 0 comments 1 reaction 0 assignees View on GitHub
feature
Dominant language
Python
Stars
14.1k
Forks
665
PR merge metrics
No merged PRs in 30d

Description

### Summary:

On systems that use AppArmor (eg. Ubuntu) every process has a security label assigned, which can be checked by reading the `/proc/pid/attr/apparmor/current` file of that process

I'd like to be able to use that label as an operand in OpenSnitch rules

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading the existing OpenSnitch rule operand handling and inspect the process label at /proc/pid/attr/apparmor/current. Done means an AppArmor label can be used as an operand in OpenSnitch rules on systems that provide it.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux
Domain
operating-systems, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.