I share the concern here. The idea that a piece of malware can exclude itself seems nasty to me. I am not an expert on writing malware, but it intuitively seems to me to be a huge opportunity for creativity. The argument that it's ok because anything that the malware writes will eventually be scanned anyway does not reassure me. Also... I was one of the people who brought up the idea of a process exclusion when the requirements list was being developed. I intended it as a way that an AV application could exclude specific OTHER processes by name (as selected by the AV user) -- not as a way that a process would exclude itself. I don't think that the implementation here reflects this goal, which still seems to me to be a requirement. Jon Press CA/HCL Internet Security Business Unit -----Original Message----- From: malware-list-bounces@dmesg.printk.net [mailto:malware-list-bounces@dmesg.printk.net] On Behalf Of Eric Paris Sent: Monday, August 04, 2008 8:33 PM To: Greg KH Cc: linux-kernel@vger.kernel.org; malware-list@lists.printk.net Subject: Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interface foron access scanningwhich the and performance. In controlled LSM all Processes can only get this flag one of 2 ways. 1) register as a client to make access decisions 2) echo 1 into the magic file to enable the flag for themselves A process can only set this flag on itself and having this flag only means that your opens and closes will not be scanned. And excluded program could write a virus and it would not be caught on close, but it would be caught on the next open. --
| Kok, Auke | Re: -mm merge plans for 2.6.23 - ioat/dma engine |
| Jeff Garzik | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg Kroah-Hartman | [PATCH 001/196] Chinese: Add the known_regression URI to the HOWTO |
| Matthew Garrett | [PATCH] Remove process freezer from suspend to RAM pathway |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
| David Miller | [GIT]: Networking |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Jens Axboe | Re: [BUG] New Kernel Bugs |
git: | |
