On Thu, Aug 14, 2008 at 08:00:05PM -0400, Rik van Riel wrote:But Pavel is raising a good question. In Eric's proposed threat model, he claimed the only thing that he was trying to solve was "scanning". Just file scanning. That implies no root privileges, but it also implied that he wasn't worried about malware running with user privileges, either. Presumbly, that would be caught and stopped by the file scanner before the malware had a chance to run; that is the execve(2) system call would also be blocked until the executable was scanned. So if that is the threat model, then the only thing libmalware.so doesn't solve is knfsd access, and it should be evaluated on that basis. If the threat model *does* include malware which is **not** caught by the AV scanner, and is running with user privileges, then there are a whole host of other attacks that we have to worry about. So let's be real clear, up front, what the threat model is, and avoid changing the model around to rule out solutions that don't fit the initially preconceived one. That's how you get to the TSA confiscating water bottles in airport security lines. - Ted --
| Amit K. Arora | [RFC] Heads up on sys_fallocate() |
| Linus Torvalds | Linux 2.6.23-rc9 and a heads-up for the 2.6.24 series.. |
| Paul Jackson | Re: cpuset-remove-sched-domain-hooks-from-cpusets |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
git: | |
| Linus Torvalds | Re: [GIT]: Networking |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| David Miller | Re: [klibc] [patch] import socket defines |
