New Anti-Trojan kernel patches -Improved and extended for OpenBSD 3.1 Release.

From: Michael A. Williams (mikeat_private)
Date: Tue Jun 11 2002 - 01:09:21 PDT

  • Next message: Kullanici Tarum: "A different type of sniffer: Hafiye"

    Our latest version of Anti-Trojan software, V2 is available as a beta
    for OpenBSD 3.1 Release only at this stage with others to follow. 
    
    V2 adds several new important Trojan Detection features with a big
    reduction in the overall impact on a running kernel. 
    
    1.Cryptographic hash checking and filtering all files loaded through the
    memory map call mmap which include 
    -Shared libraries 
    -Loadable kernel modules 
    
    2.Activation very early in the boot cycle to provide warnings against
    Trojan files waiting to execute at boot time before the secure level is
    raised. 
    
    3.Improved efficiency in terms of system rescues used, providing very
    affordable increased security capabilities. 
    
    4.Cryptographic hash checking and filtering the Execve call including
    script files and an associated interpreter as the original reference
    version did yet utilizing the
    more efficient techniques from the V2 code. 
    
    The link is:
    http://www.trojanproof.com/sigexec-obsd3.1rV2-beta1.tgz
    
    -- 
    Michael A. Williams
    Security Software Engineering and InfoSec Manager
    NetXSecure NZ Limited, http://www.nxs.co.nz
    Ph: +64.3.318.2973 Fax: +64.3.318.2975 Mob: +64.21.995.914
    



    This archive was generated by hypermail 2b30 : Tue Jun 11 2002 - 08:04:37 PDT