>> I think you might be missing the point a bit here, as the traditional Unix model thatdo, right? Is your point that Linux and Unix machines are less vulnerable to viruses? If so, that's not relevant to my point at all. A Unix machine can be a carrier, passing infections on to other vulnerable platforms (guess which one). An enterprise security system sees the entire enterprise as an integrated whole -- not just individual machines with their own separate attributes and no impact on each other at all. I'm not endorsing or opposing the proposal until I digest it further. However, I will say that while preventing infections from arriving is not foolproof, doing a scan-on-close with the option to delete or quarantine an infected file goes a long way. Jon -----Original Message----- From: Greg KH [mailto:greg@kroah.com] Sent: Tuesday, August 05, 2008 2:12 PM To: Press, Jonathan Cc: Arjan van de Ven; Eric Paris; linux-kernel@vger.kernel.org; malware-list@lists.printk.net; linux-security-module@vger.kernel.org Subject: Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinterfaceforon access scanning A: No. Q: Should I include quotations after my reply? On Tue, Aug 05, 2008 at 02:04:26PM -0400, Press, Jonathan wrote: I think you might be missing the point a bit here, as the traditional Unix model that Linux has prevents much of what the "traditional AV" products need to do, right? integral Great, then put a hook in glibc and catch all closes and then kick off your scanning. But this proposed patchset does not do much to prevent all of these, right? So how are you going about preventing the "infection from arriving" with this proposed patchset? Isn't that something that SELinux or another LSM can prevent better? thanks, greg k-h --
| Alan | Re: [RFC] Heads up on sys_fallocate() |
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg Kroah-Hartman | [PATCH 001/196] Chinese: Add the known_regression URI to the HOWTO |
| Paul Mundt | Re: 2.6.22-rc4-mm2 |
git: | |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| David Miller | Re: [GIT]: Networking |
| Frans Pop | svc: failed to register lockdv1 RPC service (errno 97). |
