Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfaceforon access scanning

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <tvrtko.ursulin@...>
Cc: Adrian Bunk <bunk@...>, <davecb@...>, Greg KH <greg@...>, Press, Jonathan <Jonathan.Press@...>, <linux-kernel@...>, <linux-security-module@...>, <malware-list@...>, Mihai Don??u <mdontu@...>, Pavel Machek <pavel@...>
Date: Wednesday, August 13, 2008 - 10:28 am

On Wed, 13 Aug 2008 15:16:12 +0100
tvrtko.ursulin@sophos.com wrote:


the biggest objection is the lack of security model description.
STILL nobody has answered Ted's questions.

And still the AV side of the argument keeps making circular arguments.


I'm not saying the kernel shouldn't be involved at all.
I can totally see a solution where we have a
sys_virus_scan(int fd)
that glibc calls at appropriate places (say every read() and mmap())
and that on the kernel side uses a cache to store which virus signature
version it was last scanned with, and if not new enough.. punts to some
userspace scanner for vetting.

but first someone needs to answer Ted's very basic questions or the
TALPA side really does look like a donkey in this argument.





-- 
If you want to reach me at my work email, use arjan@linux.intel.com
For development, discussion and tips for power savings, 
visit http://www.lesswatts.org
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Sidebar to [malware-list] [RFC 0/5] [TALPA] Intro to a linux..., David Collier-Brown, (Wed Aug 6, 7:40 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., David Collier-Brown, (Mon Aug 11, 12:11 pm)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., Arjan van de Ven, (Wed Aug 13, 10:28 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interf..., David Collier-Brown, (Wed Aug 6, 7:31 am)