From: tvrtko.ursulin@sophos.com
To: david@lang.hm
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>,
Arjan van de Ven <arjan@infradead.org>,
Adrian Bunk <bunk@kernel.org>,
capibara@xs4all.nl, Casey Schaufler <casey@schaufler-ca.com>,
davecb@sun.com, Eric Paris <eparis@redhat.com>,
linux-kernel <linux-kernel@vger.kernel.org>,
linux-security-module@vger.kernel.org,
malware-list@lists.printk.net,
malware-list-bounces@dmesg.printk.net,
Mihai Don??u <mdontu@bitdefender.com>,
Peter Dolding <oiaohm@gmail.com>, Pavel Machek <pavel@suse.cz>,
Rik van Riel <riel@redhat.com>,
rmeijer@xs4all.nl, Theodore Tso <tytso@mit.edu>
Subject: Re: [malware-list] scanner interface proposal was: [TALPA] Intro to a linux interface for on access scanning (fwd)
Date: Mon, 18 Aug 2008 13:18:58 +0100 [thread overview]
Message-ID: <20080818122003.4ACC02FE864@pmx1.sophos.com> (raw)
In-Reply-To: <alpine.DEB.1.10.0808180441560.12859@asgard.lang.hm>
david@lang.hm wrote on 18/08/2008 12:44:12:
> On Mon, 18 Aug 2008, tvrtko.ursulin@sophos.com wrote:
>
> > David Lang wrote on 18/08/2008 02:25:44:
> >
> >> what is not covered by this design that is covered by the threat
model
> > being
> >> proposed?
> >>
> >> what did I over complicate in this design? or is it the minimum
feature
> > set
> >> needed?
> >>
> >> are any of the features I list impossible to implement?
> >
> > One more thing - this proposal does not work where there are no
extended
> > attributes (whether at all or they are disabled at mount time). I
think
> > that is a serious flaw or at least disadvantage compared to the posted
> > implementation.
>
> good point. I should have listed that.
>
> I don't see it as a serious flaw, people who care about this feature can
> just pick an appropriate filesystem to use.
You mostly cannot pick not use vfat, isofs and udf.
> but if extended attributes are not found a strict implementation could
> fall back to scanning on every file access (the extended attributes are
> being used to cache the results of the scans)
Performance impact may or may not be acceptable but I dislike the concept
of core security interface which is not really core.
--
Tvrtko A. Ursulin
Senior Software Engineer, Sophos
"Views and opinions expressed in this email are strictly those of the
author.
The contents has not been reviewed or approved by Sophos."
Sophos Plc, The Pentagon, Abingdon Science Park, Abingdon,
OX14 3YP, United Kingdom.
Company Reg No 2096520. VAT Reg No GB 348 3873 20.
next prev parent reply other threads:[~2008-08-18 12:20 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-08-18 1:25 scanner interface proposal was: [TALPA] Intro to a linux interface for on access scanning (fwd) david
2008-08-18 10:30 ` [malware-list] " tvrtko.ursulin
2008-08-18 11:44 ` david
2008-08-18 12:18 ` tvrtko.ursulin [this message]
2008-08-18 12:34 ` david
2008-11-23 22:37 ` Enrico Weigelt
2008-11-23 23:03 ` Alan Cox
2008-12-01 0:51 ` Enrico Weigelt
2008-12-01 5:22 ` david
2008-12-01 10:03 ` Alan Cox
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20080818122003.4ACC02FE864@pmx1.sophos.com \
--to=tvrtko.ursulin@sophos.com \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=arjan@infradead.org \
--cc=bunk@kernel.org \
--cc=capibara@xs4all.nl \
--cc=casey@schaufler-ca.com \
--cc=davecb@sun.com \
--cc=david@lang.hm \
--cc=eparis@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=malware-list-bounces@dmesg.printk.net \
--cc=malware-list@lists.printk.net \
--cc=mdontu@bitdefender.com \
--cc=oiaohm@gmail.com \
--cc=pavel@suse.cz \
--cc=riel@redhat.com \
--cc=rmeijer@xs4all.nl \
--cc=tytso@mit.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox