Re: Comptuer Virus Help
- From: kurt wismer <kurtw@xxxxxxxxxxxx>
- Date: Wed, 15 Nov 2006 00:25:10 -0500
Sebastian Gottschalk wrote:
[snip]
Real protection against viruses is provided by ACLs, implementing a global
no-exec policy and by not allowing automatic code execution.
by acls i imagine you're making a reference to least privilege... fred cohen's early experiments with viruses demonstrate fairly unequivocally that least privilege does not stop viruses... it is a speed bump, not a road block - it will interfere with those viruses that were made with the assumption of having admin access and that's about all...
as for trying to control execution, determining executable data from non-executable data is undecidable in the general case...
they can be valuable additions to a defense in depth approach, but they are not, by themselves, a solution to the virus problem...
--
"it's not the right time to be sober
now the idiots have taken over
spreading like a social cancer,
is there an answer?"
.
- References:
- Comptuer Virus Help
- From: herbdove
- Re: Comptuer Virus Help
- From: erewhon
- Comptuer Virus Help
- Prev by Date: Re: deleted files
- Next by Date: Re: Protecting Address Book
- Previous by thread: Re: Comptuer Virus Help
- Next by thread: Re: Comptuer Virus Help
- Index(es):
Relevant Pages
|