Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfaceforon access scanning

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Arjan van de Ven <arjan@...>
Cc: Adrian Bunk <bunk@...>, <davecb@...>, Greg KH <greg@...>, Press, Jonathan <Jonathan.Press@...>, <linux-kernel@...>, <linux-security-module@...>, <malware-list@...>, Mihai Don??u <mdontu@...>, Pavel Machek <pavel@...>
Date: Wednesday, August 13, 2008 - 10:16 am

Arjan van de Ven <arjan@infradead.org> wrote on 13/08/2008 14:54:01:


LD_PRELOAD does not solve at least knfsd and suid binaries. But we are 
going in circles. :)
 

Same is true for a kernel solution. Plus, it also works for those who make 
system calls directly, knfsd and suid binaries, and we can have cheap and 
ultra-efficient caching. Not much kernel code, even less complex kernel 
code and unmeasurable impact when not used and compiled in. What are the 
big technical objections to that?

--
Tvrtko A. Ursulin
Senior Software Engineer, Sophos

"Views and opinions expressed in this email are strictly those of the 
author.
 The contents has not been reviewed or approved by Sophos."
 

Sophos Plc, The Pentagon, Abingdon Science Park, Abingdon,
OX14 3YP, United Kingdom.

Company Reg No 2096520. VAT Reg No GB 348 3873 20.

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Sidebar to [malware-list] [RFC 0/5] [TALPA] Intro to a linux..., David Collier-Brown, (Wed Aug 6, 7:40 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., David Collier-Brown, (Mon Aug 11, 12:11 pm)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., , (Wed Aug 13, 10:16 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., Arjan van de Ven, (Wed Aug 13, 10:28 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interf..., David Collier-Brown, (Wed Aug 6, 7:31 am)