Restricting the access of a web server to system resources limits the potential damage caused to those resources through exploitation of web server vulnerabilities.
data:image/s3,"s3://crabby-images/4f657/4f65714f6e70d6dfa1c30de3b31898e6db959559" alt=""
Confining the Apache Web Server with Security-Enhanced Linux
Download Resources
PDF Accessibility
One or more of the PDF files on this page fall under E202.2 Legacy Exceptions and may not be completely accessible. You may request an accessible version of a PDF using the form on the Contact Us page.
Restricting the access of a web server to system resources limits the potential damage caused to those resources through exploitation of web server vulnerabilities. However, allowing the web server to access the required resources enables the web server to provide expected functionality. This combination of denying unnecessary access and allowing required access results in providing web server functionality while limiting damage. To demonstrate this, we hosted the Apache web server on Security-Enhanced Linux, an operating system that enforces a mandatory access control policy. By tailoring the Security-Enhanced Linux policy, we were able to control interaction between the Apache web server and other processes and files on the system. The policy dictates that Apache is only allowed to display web pages and perform limited functions that support the display of web pages.