The invention provides a Linux
security policy configuration method based on self-learning aiming at the problem that Linux
security policy configuration is difficult so as to simplify the working process of
system configuration. According to the Linux
security policy configuration method, a policy study module is embedded in a security
server area of Security-Enhanced Linux (SE Linux). The module provides an
automatic learning switch for a configuration administrator user so that a security
server can automatically generate an
access control policy by judging the on-off state. When the switch is in the on-state, all access requests between subjects and objects intercepted by an LSM are recorded, corresponding
access control policies are automatically generated, and simultaneously the requests are released. When the switch is in the off-state, the policy study module no longer plays the role, and the security
server returns the existing
access control policies. The policies generated with the Linux security policy configuration method in the self-learning mode all meet the requirements of minimum privilege of the subjects, hidden safety dangers or stability dangers caused by errors in manual configuration can be avoided to the maximum extent, and
system safety can be further improved.