1 Internal use only
Widely Used But Out-Of-Tree
Kees Cook
(that's pronounced “Case”) kees.cook@canonical.com
Widely Used But Out-Of-Tree Kees Cook (that's pronounced Case) - - PowerPoint PPT Presentation
Widely Used But Out-Of-Tree Kees Cook (that's pronounced Case) kees.cook@canonical.com Linux Security Summit Boston, Aug 2010 http://people.canonical.com/~kees/slides/out-of-tree.pdf Internal use only 1 Agenda Past
1 Internal use only
(that's pronounced “Case”) kees.cook@canonical.com
2 Internal use only
3 Internal use only
4 Internal use only
5 Internal use only
6 Internal use only
– OpenWall, grsecurity, Ubuntu
– grsecurity, RedHat/Fedora, SUSE, Ubuntu
– RedHat/Fedora, SUSE, Ubuntu (partially)
– grsecurity, Ubuntu
7 Internal use only
8 Internal use only
9 Internal use only
10 Internal use only
– defense against attack is, like biological systems, a matter of probability – better to have an imperfect heuristic than a missing perfect system – work around changes in userspace semantics (we are, after all, a Free Software community, right?) – “perfect” is absolutely impossible (kernel vulnerabilities frequently undermine all other defense systems)
11 Internal use only
12 Internal use only