• Each SELinux access control model is simple, but actually access control is more complex • Red Hat puts a lot of effort into SELinux, policy and utils for SELinux usability – Enlarging default policy modules – Encouraging Policy module system – Analyzing and generating policies from access violation log