login
Login
/
Register
Search
Forums
News
Blogs
Features
Site
Home
»
Mailing list archives
»
linux-kernel
»
2008
»
August
»
18
Re: TALPA - a threat model? well sorta.
view
thread
!MAILaRCHIVE_VOTE_RePLACE
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
[view in full thread]
From:
Pavel Machek <pavel@...>
To: <david@...>
Cc: Arjan van de Ven <arjan@...>, Eric Paris <eparis@...>, <linux-kernel@...>, <malware-list@...>, <andi@...>, <riel@...>, <greg@...>, <tytso@...>, <viro@...>, <alan@...>, <peterz@...>, <hch@...>
Subject:
Re: TALPA - a threat model? well sorta.
Date: Monday, August 18, 2008 - 9:30 am
Hi!
quoted text
> >How does it work? Memory can still change after mmap; > >scanning at the > >mmap time is _NOT_ enough. > > > >You could do 'when app attempts to dirty memory, > >synchronously unmap > >it from all apps that have it mapped' and then do sync > >scan on > >pagefault time; but that sounds impractical. > > what is the threat you are trying to defend against? > > for some threats you are right, for others the scan at > mmap time is enough.
I don't see any threats when check at mmap time is okay. As soon as file servers use mmap, this race can bite you even in very simple 'make sure Linux fileserver does not pass on windows malwar' threat model. Pavel -- (english)
http://www.livejournal.com/~pavelmachek
(cesky, pictures)
http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html
--
unsubscribe notice
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to
majordomo@vger.kernel.org
More majordomo info at
http://vger.kernel.org/majordomo-info.html
Please read the FAQ at
http://www.tux.org/lkml/
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
Messages in current thread:
TALPA - a threat model? well sorta.
, Eric Paris
, (Wed Aug 13, 12:36 pm)
Re: TALPA - a threat model? well sorta.
, 7v5w7go9ub0o
, (Wed Aug 13, 8:14 pm)
Re: TALPA - a threat model? well sorta.
, 7v5w7go9ub0o
, (Wed Aug 13, 10:25 pm)
Re: TALPA - a threat model? well sorta.
, Andi Kleen
, (Wed Aug 13, 2:17 pm)
Re: TALPA - a threat model? well sorta.
, Mihai
, (Wed Aug 13, 8:18 pm)
RE: [malware-list] TALPA - a threat model? well sorta.
, Press, Jonathan
, (Thu Aug 14, 7:58 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Mihai
, (Thu Aug 14, 8:34 am)
Re: TALPA - a threat model? well sorta.
, Eric Paris
, (Wed Aug 13, 2:40 pm)
Re: TALPA - a threat model? well sorta.
, H. Peter Anvin
, (Wed Aug 13, 2:21 pm)
Re: TALPA - a threat model? well sorta.
, Arjan van de Ven
, (Wed Aug 13, 2:24 pm)
Re: TALPA - a threat model? well sorta.
, Arjan van de Ven
, (Wed Aug 13, 1:39 pm)
Re: TALPA - a threat model? well sorta.
, Pavel Machek
, (Fri Aug 15, 12:06 pm)
Re: TALPA - a threat model? well sorta.
,
, (Mon Aug 18, 8:21 am)
Re: TALPA - a threat model? well sorta.
, Pavel Machek
, (Mon Aug 18, 9:30 am)
Re: TALPA - a threat model? well sorta.
,
, (Mon Aug 18, 8:03 pm)
Re: TALPA - a threat model? well sorta.
,
, (Thu Aug 14, 9:31 pm)
Re: TALPA - a threat model? well sorta.
, Eric Paris
, (Wed Aug 13, 2:57 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Thu Aug 14, 5:46 am)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Thu Aug 14, 9:37 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Arjan van de Ven
, (Thu Aug 14, 9:46 am)
Re: TALPA - a threat model? well sorta.
, Arjan van de Ven
, (Wed Aug 13, 5:39 pm)
Re: TALPA - a threat model? well sorta.
, Eric Paris
, (Thu Aug 14, 10:12 am)
Re: TALPA - a threat model? well sorta.
, Helge Hafting
, (Fri Aug 15, 6:07 am)
Re: TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 6:44 am)
Re: TALPA - a threat model? well sorta.
, Peter Zijlstra
, (Fri Aug 15, 6:37 am)
RE: [malware-list] TALPA - a threat model? well sorta.
, Press, Jonathan
, (Fri Aug 15, 9:10 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Helge Hafting
, (Mon Aug 18, 6:02 am)
RE: [malware-list] TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 12:25 pm)
RE: [malware-list] TALPA - a threat model? well sorta.
, Press, Jonathan
, (Fri Aug 15, 12:30 pm)
RE: [malware-list] TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 1:33 pm)
RE: [malware-list] TALPA - a threat model? well sorta.
, Press, Jonathan
, (Fri Aug 15, 1:40 pm)
RE: [malware-list] TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 1:47 pm)
RE: [malware-list] TALPA - a threat model? well sorta.
, Press, Jonathan
, (Fri Aug 15, 2:17 pm)
RE: [malware-list] TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 4:08 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 2:06 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Theodore Tso
, (Fri Aug 15, 4:17 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 4:05 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 9:18 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Theodore Tso
, (Fri Aug 15, 1:04 pm)
RE: [malware-list] TALPA - a threat model? well sorta.
, Press, Jonathan
, (Fri Aug 15, 2:09 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Helge Hafting
, (Mon Aug 18, 6:09 am)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Mon Aug 18, 6:25 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Peter Zijlstra
, (Mon Aug 18, 6:14 am)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Mon Aug 18, 6:24 am)
Re: TALPA - a threat model? well sorta.
, Arjan van de Ven
, (Thu Aug 14, 11:57 am)
Re: TALPA - a threat model? well sorta.
, Theodore Tso
, (Wed Aug 13, 2:15 pm)
Re: TALPA - a threat model? well sorta.
, Eric Paris
, (Wed Aug 13, 3:02 pm)
Re: TALPA - a threat model? well sorta.
, Theodore Tso
, (Wed Aug 13, 3:29 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Thu Aug 14, 5:30 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Theodore Tso
, (Thu Aug 14, 9:24 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Eric Paris
, (Thu Aug 14, 9:48 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Theodore Tso
, (Thu Aug 14, 11:50 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Pavel Machek
, (Fri Aug 15, 10:37 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Eric Paris
, (Thu Aug 14, 1:29 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Theodore Tso
, (Thu Aug 14, 3:17 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Christoph Hellwig
, (Thu Aug 14, 3:34 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Theodore Tso
, (Thu Aug 14, 3:41 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Thu Aug 14, 9:44 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Theodore Tso
, (Thu Aug 14, 10:04 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Alan Cox
, (Fri Aug 15, 4:51 am)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 12:48 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Arjan van de Ven
, (Thu Aug 14, 11:41 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 1:05 am)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 1:36 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Johannes Weiner
, (Fri Aug 15, 1:12 am)
Re: [malware-list] TALPA - a threat model? well sorta.
,
, (Fri Aug 15, 1:28 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Christoph Hellwig
, (Thu Aug 14, 4:20 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, J. Bruce Fields
, (Thu Aug 14, 5:21 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Theodore Tso
, (Thu Aug 14, 7:34 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, J. Bruce Fields
, (Tue Aug 19, 5:43 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Eric Paris
, (Thu Aug 14, 3:20 pm)
RE: [malware-list] TALPA - a threat model? well sorta.
, Press, Jonathan
, (Thu Aug 14, 8:03 am)
RE: [malware-list] TALPA - a threat model? well sorta.
,
, (Thu Aug 14, 8:27 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Pavel Machek
, (Fri Aug 15, 10:31 am)
RE: [malware-list] TALPA - a threat model? well sorta.
, Press, Jonathan
, (Wed Aug 13, 5:15 pm)
Re: TALPA - a threat model? well sorta.
, Arjan van de Ven
, (Wed Aug 13, 2:21 pm)
Re: TALPA - a threat model? well sorta.
,
, (Thu Aug 14, 5:18 am)
Re: TALPA - a threat model? well sorta.
, Greg KH
, (Wed Aug 13, 12:57 pm)
Re: TALPA - a threat model? well sorta.
, Alan Cox
, (Wed Aug 13, 12:24 pm)
Re: TALPA - a threat model? well sorta.
, Arnd Bergmann
, (Thu Aug 14, 9:00 am)
Re: TALPA - a threat model? well sorta.
, Christoph Hellwig
, (Wed Aug 13, 1:07 pm)
Re: TALPA - a threat model? well sorta.
, Eric Paris
, (Wed Aug 13, 12:47 pm)
Re: TALPA - a threat model? well sorta.
, Alan Cox
, (Wed Aug 13, 12:37 pm)
Re: TALPA - a threat model? well sorta.
, Eric Paris
, (Wed Aug 13, 1:00 pm)
Re: TALPA - a threat model? well sorta.
, Alan Cox
, (Wed Aug 13, 3:59 pm)
RE: [malware-list] TALPA - a threat model? well sorta.
, Press, Jonathan
, (Wed Aug 13, 5:24 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Rik van Riel
, (Wed Aug 13, 5:35 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Jan Harkes
, (Fri Aug 15, 4:16 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Arjan van de Ven
, (Fri Aug 15, 6:05 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Eric Paris
, (Sun Aug 17, 7:19 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Alan Cox
, (Mon Aug 18, 11:33 am)
Re: [malware-list] TALPA - a threat model? well sorta.
, Rik van Riel
, (Mon Aug 18, 12:43 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Arjan van de Ven
, (Sun Aug 17, 7:26 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, David Collier-Brown
, (Sun Aug 17, 5:11 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Alan Cox
, (Wed Aug 13, 5:23 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Eric Paris
, (Thu Aug 14, 11:25 pm)
Re: [malware-list] TALPA - a threat model? well sorta.
, Alan Cox
, (Wed Aug 13, 5:13 pm)
Navigation
Create content
Mailing list archives
Recent posts
Popular discussions
linux-kernel
:
Max Krasnyansky
Re: Inquiry: Should we remove "isolcpus= kernel boot option? (may have realtime us...
Jeremy Allison
Re: [RFC] Heads up on sys_fallocate()
Randy Dunlap
Re: -mm merge plans for 2.6.23 (pcmcia)
Damien Wyart
ACPI power off regression in 2.6.23-rc8 (NOT in rc7)
git
:
linux-netdev
:
Josip Rodin
Re: bnx2_poll panicking kernel
Linus Torvalds
Re: [GIT]: Networking
Denys Fedoryshchenko
thousands of classes, e1000 TX unit hang
openbsd-misc
:
Colocation donated by:
Who's online
There are currently
5 users
and
893 guests
online.
Online users
mats28nicu
strcmp
jakecapri
bedandbreakfas
backlinkservchp
Syndicate