Thread (13 messages) flat view 13 messages, 2 authors, 2021-03-12

Re: [PATCH v5 7/8] Documentation: Add documentation for the Brute LSM

From: Andi Kleen <hidden>
Date: 2021-03-07 15:20:06
Also in: linux-kselftest, linux-security-module, lkml

Sorry for the late answer. I somehow missed your email earlier.
As a mitigation method, all the offending tasks involved in the attack are
killed. Or in other words, all the tasks that share the same statistics
(statistics showing a fast crash rate) are killed.
So systemd will just restart the network daemon and then the attack works
again?

Or if it's a interactive login you log in again.

I think it might be useful even with these limitations, but it would
be good to spell out the limitations of the method more clearly.

I suspect to be useful it'll likely need some user space configuration
changes too.

-Andi
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help