How much entropy is actually gained ?
How much entropy is actually gained ?
Posted May 13, 2017 17:57 UTC (Sat) by zlynx (guest, #2285)In reply to: How much entropy is actually gained ? by moltonel
Parent article: Randomizing structure layout
The biggest advantage to these things is that it tends to remove stealth from attacks. The system administrator should notice repeated kernel BUG outputs and/or system crashes caused by overwriting random struct fields.
With a perfect attack script, the administrator never notices anything wrong and the attack leaves no traces.
Once an attack is noticed, the machine can be turned into a honeypot with full network recording. On the next attack, you've then got the complete log of how it was done, and can find and patch the bug.
It's the difference between breaking into a building with a copied key or lockpicks, vs. breaking the glass and setting off the alarm.