---
title: An introduction to AppArmor
description: Cyber attacks are becoming more sophisticated, attack frequency is on
  the rise, and the cost of cybercrime damage is projected to reach $6 trillion annually
  by 2021. Traditional defensive measures such as firewalls and intrusion detection
  systems that operate at the network perimeter are no longer enough to protect today’s
  distributed ent […]
url: https://canonical.com/blog/an-introduction-to-apparmor?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Sarah Dickinson](https://canonical.com/blog/author/sarahfd "More about Sarah Dickinson")

26 April 2019

# An introduction to AppArmor

[apparmor](https://canonical.com/blog/tag/apparmor)
[Apps](https://canonical.com/blog/tag/apps)
[Security](https://canonical.com/blog/tag/security)
[Snaps](https://canonical.com/blog/tag/snaps)

---

Share the article

Cyber attacks are becoming more sophisticated, attack frequency is on the rise, and the cost of cybercrime damage is projected to reach [$6 trillion annually by 2021](https://cybersecurityventures.com/top-5-cybersecurity-facts-figures-predictions-and-statistics-for-2019-to-2021/). Traditional defensive measures such as firewalls and intrusion detection systems that operate at the network perimeter are no longer enough to protect today’s distributed enterprise networks. Rather, a ‘defence in depth’ approach is required in order to protect all facets of an organisation’s digital infrastructure.

In an ideal world, applications would be free from security vulnerabilities but, once compromised, even a trusted application can become untrustworthy. [AppArmor](https://wiki.ubuntu.com/AppArmor) provides a crucial layer of security around applications. By providing the capability to whitelist an application’s permissible actions, AppArmor enables administrators to apply the principle of least privilege to applications. Once in place, AppArmor can halt attacks and minimise or prevent damage in the event of a breach.

This whitepaper provides a technical introduction to AppArmor, including:

* Why a ‘defence in depth’ strategy should be employed to mitigate the potential damage caused by a breach
* An explanation of AppArmor, its key features and why the principle of least privilege is recommended
* The use of AppArmor in Ubuntu and snaps

First Name:

Last Name:

Work email:

Company Name:

Job Title:

Phone Number:

I agree to receive information about Canonical’s products and services.

In submitting this form, I confirm that I have read and agree to
[Canonical’s Privacy Notice](https://canonical.com/legal/data-privacy/contact) and [Privacy Policy](https://canonical.com/legal/data-privacy).

Download

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Canonical joins the Open Secure AI Alliance](https://canonical.com/blog/open-secure-ai-alliance)

Canonical is now part of the Open Secure AI Alliance, announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and...

[Canonical](https://canonical.com/blog/author/canonical)

28 August 2026

[### Januscape vulnerability CVE-2026-53359 mitigations available](https://canonical.com/blog/januscape-linux-vulnerability-mitigations-available)

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID...

[seth-arnold](https://canonical.com/blog/author/seth-arnold)

11 July 2026

[### DirtyClone Linux kernel local privilege escalation vulnerability fixes available](https://canonical.com/blog/dirtyclone-linux-vulnerability-fixes-available)

On June 25, 2026, JFrog published their research into CVE-2026-43503, referring to the vulnerability as DirtyClone. The vulnerability had previously been responsibly disclosed...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026

[### pedit COW kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/pedit-cow-linux-vulnerability-fixes-available)

Mitigations are available for the Linux vulnerability with CVE ID CVE-2026-46331. The CVE ID was assigned on June 16 2026 and highlighted as a local privilege escalation (LPE)...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026
