Главная
Study mode:
on
1
Intro
2
Why is this important
3
Bugfighting
4
Car analogy
5
Killing bugs
6
Killing bug classes
7
Exploitation methods
8
Memory safety languages
9
Kernel Subduction Project
10
Kernel Updates
11
Vulnerabilities
12
Conversions
13
Bugs
14
More conversions
15
Expected for 53
16
Upcoming features
17
Challenges
18
Questions
Description:
Explore the latest developments in the Kernel Self-Protection Project in this 25-minute conference talk by Kees Cook from Google. Gain insights into the project's efforts to eliminate bug classes and block kernel exploitation techniques. Learn about security defenses implemented in kernels 4.19 through 5.3, including stack and heap auto-initialization, heap mapping robustness, per-task stack canaries, VLA removal, and implicit-fallthrough removal. Discover the progress on upstreaming Control Flow Integrity (CFI) and examine the evolution of kernel CVE lifetimes. Get an overview of ongoing defense developments and areas requiring further assistance. The presentation covers topics such as bugfighting, exploitation methods, memory safety languages, and upcoming features, concluding with a discussion of challenges and a Q&A session.

Kernel Self-Protection Project: Eliminating Bug Classes and Blocking Exploitation Techniques

Linux Foundation
Add to list
0:00 / 0:00