|
|
Subscribe / Log in / New account

Handling brute force attacks in the kernel

Handling brute force attacks in the kernel

Posted Mar 18, 2021 12:55 UTC (Thu) by walters (subscriber, #7396)
Parent article: Handling brute force attacks in the kernel

I haven't followed closely, but https://lwn.net/Articles/808048/ seems a lot more promising to me because it allows lifting all these heuristics out of the kernel - a hybrid eBPF + userspace process can access more semantic information; say things like "did this process receive packets from an untrusted network recently". And it can be much more configurable, e.g. one could easily recode it to force a process like this to dump core for offline analysis instead, etc.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds