Re: [malware-list] [RFC 0/5] [TALPA] Intro to alinuxinterfaceforon access scanning

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: david
Date: Sunday, August 17, 2008 - 4:24 pm

On Mon, 18 Aug 2008, Pavel Machek wrote:


no, but can you tell at the time of the mmap command if anyone has it 
opened for writing? if you can then you can just not allow the mmap in 
thid case (policy decision by userspace, as such it can try to look at 
what other programs are accessing it via mmap to decide if it should allow 
it or not)


I listed that as an example of what I would consider a sane policy. by 
doing the checking is a userspace library different binaries can be linked 
against different libraries by the sysadmin/distro to decide which ones 
need to do what checking. there's nothing inherent in the mechanism that 
foces the policy in any direction.

David Lang
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux inte ..., David Collier-Brown, (Wed Aug 6, 4:31 am)
Sidebar to [malware-list] [RFC 0/5] [TALPA] Intro to a lin ..., David Collier-Brown, (Wed Aug 6, 4:40 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinter ..., David Collier-Brown, (Mon Aug 11, 9:11 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to alinuxinterf ..., david, (Sun Aug 17, 4:24 pm)