oss-sec mailing list archives
Re: Data on Linux attacks (was Re: [oss-security] Re: Fwd: x86 ROP mitigation)
From: Kurt Seifried <kseifried () redhat com>
Date: Wed, 18 Nov 2015 07:31:47 -0700
On Wed, Nov 18, 2015 at 6:13 AM, Josh Bressers <bressers () redhat com> wrote:
We face the problem that I and my immediate colleagues (on the Red Hat tools team) do not have access to information about successful compromises, and what attackers actually do today, on GNU/Linux systems, both to achieve initial access and to maintain a presence afterwards. Under these conditions, anything we implement is, to some degree, arbitrary and a shot in the dark. We can still use our best judgment to set priorities, but we are very far from being guided by empiricalevidence.This is a place I think we could all stand to work together on. If anyone has any information on Linux attacks it would be very useful for planning future projects. There is a lot of evidence against some other platforms, but I've not seen anything great around Linux specifically. If anyone has ideas or comments, I'm all ears. -- JB
I know a lot of cloud providers use various indicators (e.g. memory/cpu/network/disk usage), or straight up IDS to detect compromised/suspicious hosts, but due to the nature of the cloud market they simply inform the account, they do not look into the data in the account directly (e.g. with a human) under any circumstances due to privacy policy/etc. So this removes a huge set of potential data. Same problem as Red Hat faces, we can't simply harvest huge amounts of customer data due to privacy and legal concerns. We would have to rely upon the compromised users coming forth with details/forensic results, so anecdotal, self selected data at best. I know in my experience I had seifried.org hacked many years ago due to a combination of known web based vuln (which I was going to patch as soon as an update came out) and a Kernel local escalation vuln (which I was planning to patch on Monday, but it was a weekend). I also had a full SSH trust setup for all the hosts because I was super lazy, so once they got into the web host they got into all the hosts. Needless to say I don't do things like that anymore. I know the CloudSecurityAlliance.org is working on a platform to provide anonymized information sharing of incidents/attacks, and various other organizations like Infragard have similar programs setup, maybe we can ask nicely for meta data from them. Another alternative is to setup enough honeypots that we get meaningful data, but again this would be self selecting to some degree as we wouldn't see as many APT attacks. -- Kurt Seifried -- Red Hat -- Product Security -- Cloud PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 Red Hat Product Security contact: secalert () redhat com
Current thread:
- Re: Re: Fwd: x86 ROP mitigation, (continued)
- Re: Re: Fwd: x86 ROP mitigation Daniel Micay (Nov 17)
- Re: Re: Fwd: x86 ROP mitigation Josh Bressers (Nov 17)
- Re: Re: Fwd: x86 ROP mitigation Daniel Micay (Nov 17)
- Re: Re: Fwd: x86 ROP mitigation Josh Bressers (Nov 17)
- Re: Re: Fwd: x86 ROP mitigation Daniel Micay (Nov 17)
- Re: Re: Fwd: x86 ROP mitigation Rich Felker (Nov 17)
- Re: Re: Fwd: x86 ROP mitigation Daniel Micay (Nov 17)
- Re: Fwd: x86 ROP mitigation Solar Designer (Nov 17)
- Re: Fwd: x86 ROP mitigation Florian Weimer (Nov 18)
- Data on Linux attacks (was Re: [oss-security] Re: Fwd: x86 ROP mitigation) Josh Bressers (Nov 18)
- Re: Data on Linux attacks (was Re: [oss-security] Re: Fwd: x86 ROP mitigation) Kurt Seifried (Nov 18)
- Re: Re: Fwd: x86 ROP mitigation Steve Grubb (Nov 18)
- Re: Re: Fwd: x86 ROP mitigation Fabio Pagani (Nov 18)
- Re: Fwd: x86 ROP mitigation Solar Designer (Nov 19)
- Re: Re: Fwd: x86 ROP mitigation Jonathan Salwan (Nov 19)
- Re: Fwd: x86 ROP mitigation Solar Designer (Nov 17)
- Re: Fwd: x86 ROP mitigation Bernd Schmidt (Nov 18)
- Re: Re: Fwd: x86 ROP mitigation Florian Weimer (Nov 18)
- Re: Fwd: x86 ROP mitigation Jeff Law (Nov 18)
