WhiteEgret: New Linux Security Module For Execution Whitelisting

Status
Not open for further replies.

Handsome Recluse

Level 23
Thread author
Verified
Top Poster
Well-known
Nov 17, 2016
1,242
WhiteEgret: New Linux Security Module For Execution Whitelisting - Phoronix
WhiteEgret is the name of a new Linux Security Module (LSM) in-development by Toshiba for being able to limit what your system can execute via a whitelist.

Masanobu Koike of Toshiba has described of WhiteEgret:

An execution-whitelist, simply called whitelist, is a list of executable components (e.g., applications, libraries) that are approved to run on a host. The whitelist is used to decide whether executable components are permitted to execute or not. This mechanism can stop an execution of unknown software, so it helps to stop the execution of malicious code and other unauthorized software. The whitelisting-type execution control works best in the execution environments that are not changed for a long time, for example, servers and control devices in industrial control systems. This RFC provides a whitelisting-type execution control implementation WhiteEgret.
WhiteEgret prides itself on an easy setup process, shortened downtime, less restrictions on the operational environment, and more.

This new Linux Security Module is just over two thousand lines of new code and is currently available for review via the kernel mailing list. More details via the patch series.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top