Language Selection

English French German Italian Portuguese Spanish

Kernel space: Virus scanning API spawns security debate

Filed under
Linux

The TALPA malware scanning API was covered in LWN in December, 2007. Several months later, TALPA is back - in the form of a patch set posted by a Red Hat employee. The resulting discussion has certainly not been what the TALPA developers would have hoped for; it is, instead, a good example of how a potentially useful idea can be set back by poor execution and presentation to the kernel community.

The idea behind TALPA is simple: various companies in the virus-scanning business would like a hook into the kernel which allows them to check for malware and prevent its spread. So the patch adds a hook into the VFS code which intercepts every file open operation. A series of filters can be attached to this intercept, with the most important one being a mechanism which makes the file being opened available to a user-space process as a read-only file descriptor. That process can scan the file and tell the kernel whether the open operation should be allowed to proceed or not. In this way, the scanning process can prevent any sort of access to files which are deemed to contain bits with evil intentions.

There are a few other details, of course. A caching mechanism prevents rescanning of unchanged files, increasing performance considerably.

More here




More in Tux Machines

Lubuntu 15.10 Alpha 2 Is Ready for Download, Still Using the LXDE Desktop Environment

The development team behind Lubuntu, an open-source and freely distributed flavor of the popular Ubuntu Linux operating system, announced a few minutes ago the release of the second Alpha build for the upcoming Lubuntu 15.10 (Wily Werewolf) distribution. Read more

Ubuntu Kylin 15.10 Alpha 2 Is Out for Testing with Linux Kernel 4.1, More

The development team behind the Ubuntu Kylin computer operating system have announced earlier today the immediate availability for download and testing of the second Alpha build of the upcoming Ubuntu Kylin 15.10 (Wily Werewolf) distro. Read more

Linux-powered smart sniper rifle can be hacked

Two years ago, TrackingPoint burst on to the scene with a Linux-powered smart sniper rifle that took the guesswork out of killshots. Now, however, a pair of hackers have figured out how to make it miss every single time. Read more

5 heroes of the Linux world

Linux and open source is driven by passionate people who write best-of-breed software and then release the code to the public so anyone can use it, without any strings attached. (Well, there is one string attached and that’s licence.) Who are these people? These heroes of the Linux world, whose work affects all of us every day. Allow me to introduce you. Read more