TOMOYO Linux – Mandatory Access Control (MAC) implementation

TOMOYO Linux is a Mandatory Access Control (MAC) implementation for Linux operating systems. It helps to increase the security of a system, and offers administrators a competent system analysis tool.

The MAC implementation is lightweight and usable with “automatic policy configuring” feature by “LEARNING mode”, an administrators’ friendly policy language, with no need for libselinux or userland program modifications.

TOMOYO Linux consists of patches to Linux kernel and administrative utilities. When configured to restrict access, TOMOYO Linux restricts each process to only these declared behaviors and resources (like an operation watchdog). The main tool used by TOMOYO Linux is the policy editor. This provides a number of screens that serve different roles.

Features include:

  • System analysis:
    • Debug applications.
    • Understand the behaviour of a Linux system.
    • Write documentation.
  • Increased security through Mandatory Access Control:
    • Restrict services.
    • Restrict system administrator operations.
    • Create per-application network firewalls.
    • Reduce impact from buffer overflows and other security exploits.
    • Deploy a honeypot system to detect and counteract attempts at unauthorised use.
  • Automatic policy generation.
  • Simple syntax.
  • Ease of use.
  • No changes needed to existing binaries.

Website: tomoyo.osdn.jp
Support: Documentation
Developer: NTT Data Corporation
License: GNU GPL v2

Tomoyo Linux

TOMOYO Linux is written in C. Learn C with our recommended free books and free tutorials.

Return to MAC/RBAC Tools Home Page


Ongoing series
Linux for StartersNew to Linux? Read our Linux for Starters series.
Free and Open Source SoftwareThe largest compilation of the best free and open source software in the universe. Supplied with our legendary ratings charts.
Linux ReviewsHundreds of in-depth reviews offering our unbiased and expert opinion on software.
Alternatives to GoogleAlternatives to Google's Products and Services examines your options to migrate from the Google ecosystem with open source Linux alternatives.
Linux System ToolsEssential Linux system tools looks at small, indispensable utilities, useful for system administrators as well as regular users.
Linux ProductivityLinux utilities to maximise your productivity. Small, indispensable tools, useful for anyone running a Linux machine.
Home Computer EmulatorsHome computers became commonplace in the 1980s. Emulate home computers such as the ZX81, Amstrad CPC, and ZX Spectrum.
Now and ThenNow and Then examines how promising open source software fared over the years.
Linux at HomeLinux at Home looks at a range of home activities where Linux can play its part, making the most of our time at home, keeping active and engaged.
Linux CandyLinux Candy opens up to the lighter side of Linux. Have some fun!
Best Free Android AppsBest Free Android Apps. There's a strict eligibility criteria for inclusion in this series
Programming BooksThese best free books accelerate your learning of every programming language
Programming TutorialsThese free tutorials offer the perfect tonic to the free programming books series
Stars and StripesStars and Stripes is an occasional series looking at the impact of Linux in the USA
Share this article

Share your Thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.