RE: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interface foron access scanning

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Eric Paris <eparis@...>, Greg KH <greg@...>
Cc: <linux-kernel@...>, <malware-list@...>
Date: Tuesday, August 5, 2008 - 10:41 am

I share the concern here.  The idea that a piece of malware can exclude
itself seems nasty to me.  I am not an expert on writing malware, but it
intuitively seems to me to be a huge opportunity for creativity.  The
argument that it's ok because anything that the malware writes will
eventually be scanned anyway does not reassure me.

Also...  I was one of the people who brought up the idea of a process
exclusion when the requirements list was being developed.  I intended it
as a way that an AV application could exclude specific OTHER processes
by name (as selected by the AV user) -- not as a way that a process
would exclude itself.  I don't think that the implementation here
reflects this goal, which still seems to me to be a requirement.


Jon Press
CA/HCL Internet Security Business Unit




-----Original Message-----
From: malware-list-bounces@dmesg.printk.net
[mailto:malware-list-bounces@dmesg.printk.net] On Behalf Of Eric Paris
Sent: Monday, August 04, 2008 8:33 PM
To: Greg KH
Cc: linux-kernel@vger.kernel.org; malware-list@lists.printk.net
Subject: Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interface
foron access scanning

which
the
and
performance. In
controlled
LSM
all

Processes can only get this flag one of 2 ways.

1) register as a client to make access decisions
2) echo 1 into the magic file to enable the flag for themselves

A process can only set this flag on itself and having this flag only
means that your opens and closes will not be scanned.  And excluded
program could write a virus and it would not be caught on close, but it
would be caught on the next open.


--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
RE: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interf..., Press, Jonathan, (Tue Aug 5, 10:41 am)
Sidebar to [malware-list] [RFC 0/5] [TALPA] Intro to a linux..., David Collier-Brown, (Wed Aug 6, 7:40 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., David Collier-Brown, (Mon Aug 11, 12:11 pm)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfa..., Arjan van de Ven, (Wed Aug 13, 10:28 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interf..., David Collier-Brown, (Wed Aug 6, 7:31 am)