Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interface for on access scanning

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Eric Paris
Date: Thursday, August 7, 2008 - 7:15 pm

On Fri, 2008-08-08 at 04:06 +0200, Rene Herman wrote:

but you already say that said blob exists on disk?  Therefore by my most
basic of models it won't ever actually get to run since it will get
scanned right as you try to execute it and you will get EPERM instead of
a running evil process.  (all of that is assuming the userspace black
magic is useful, but I don't think that's really up for debate since we
have no way of knowing exactly what these closed source AV vendors
actually are doing....)

It looks in my mind that more and more the only real model that can even
attempt to be addressed is to make disks inhospitable to data which
might be intended to do ill to another machine.

Once the process is running we are talking about an IDS right?


maybe a good idea, but beyond my expertise or ability to push forward...

-Eric

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux inte ..., David Collier-Brown, (Wed Aug 6, 4:31 am)
Sidebar to [malware-list] [RFC 0/5] [TALPA] Intro to a lin ..., David Collier-Brown, (Wed Aug 6, 4:40 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux inte ..., Eric Paris, (Thu Aug 7, 7:15 pm)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinter ..., David Collier-Brown, (Mon Aug 11, 9:11 am)