The software, called AppArmor, is one of several products in the security realm based on the idea of mandatory access controls. The technology limits a running software program's privileges only to those absolutely necessary.
Novell's chief rival, Red Hat, has been adding such features into its product through the use of, added to .
AppArmor lets an administrator create a profile that describes which files a given application may use. The software then enforces that profile. Consquently, if a remote attacker takes over that application, it's more difficult for the attacker to use the application for malicious purposes, such as taking over the entire computer.
Novell argues that AppArmor is "much easier to use than SELinux," according to the project's Web site. Policy generation is automated, configuration can be handled through Suse's YAST tool, Novell said. In addition, the performance penalty--a measure of the effect of the software on a system's performance--ranges from 0 percent to 2 percent compared with SELinux's 7 percent, the company added.
AppArmor is being released under the, or GPL, Novell said.