On Fri, 2008-08-08 at 04:06 +0200, Rene Herman wrote:
but you already say that said blob exists on disk? Therefore by my most
basic of models it won't ever actually get to run since it will get
scanned right as you try to execute it and you will get EPERM instead of
a running evil process. (all of that is assuming the userspace black
magic is useful, but I don't think that's really up for debate since we
have no way of knowing exactly what these closed source AV vendors
actually are doing....)
It looks in my mind that more and more the only real model that can even
attempt to be addressed is to make disks inhospitable to data which
might be intended to do ill to another machine.
Once the process is running we are talking about an IDS right?
maybe a good idea, but beyond my expertise or ability to push forward...
-Eric
--