I share the concern here. The idea that a piece of malware can exclude itself seems nasty to me. I am not an expert on writing malware, but it intuitively seems to me to be a huge opportunity for creativity. The argument that it's ok because anything that the malware writes will eventually be scanned anyway does not reassure me. Also... I was one of the people who brought up the idea of a process exclusion when the requirements list was being developed. I intended it as a way that an AV application could exclude specific OTHER processes by name (as selected by the AV user) -- not as a way that a process would exclude itself. I don't think that the implementation here reflects this goal, which still seems to me to be a requirement. Jon Press CA/HCL Internet Security Business Unit -----Original Message----- From: malware-list-bounces@dmesg.printk.net [mailto:malware-list-bounces@dmesg.printk.net] On Behalf Of Eric Paris Sent: Monday, August 04, 2008 8:33 PM To: Greg KH Cc: linux-kernel@vger.kernel.org; malware-list@lists.printk.net Subject: Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interface foron access scanningwhich the and performance. In controlled LSM all Processes can only get this flag one of 2 ways. 1) register as a client to make access decisions 2) echo 1 into the magic file to enable the flag for themselves A process can only set this flag on itself and having this flag only means that your opens and closes will not be scanned. And excluded program could write a virus and it would not be caught on close, but it would be caught on the next open. --
| Ingo Molnar | Re: x86: 4kstacks default |
| Stephen Rothwell | Re: Announce: Linux-next (Or Andrew's dream :-)) |
| Trent Piepho | [PATCH] [POWERPC] Improve (in|out)_beXX() asm code |
| Rafael J. Wysocki | [Bug #10919] [regression] display dimming is slow and laggy - Acer Travelmate 661lci |
git: | |
| Linus Torvalds | Re: iptables very slow after commit 784544739a25c30637397ace5489eeb6e15d7d49 |
| Andrew Morton | Re: [BUG] New Kernel Bugs |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
