3 ms·
I'm on mobile so links are annoying to get, but Apple has a great PDF on iOS security in general, which includes details on their protections against kernel pat
by tetrep 10y ago
I'm on mobile so links are annoying to get, but Apple has a great PDF on iOS security in general, which includes details on their protections against kernel patching. Windows has KPP, and Mac OS has SIP. Not familiar with anything for Linix but I'd be shocked if there weren't multiple incompatible implementations of similar features.
Realistically, this is also something virtualization can help guard against. If your OS is initialized from a known good version external to the VM, every time the VM starts, you greatly increase the difficulty for an attacker to get persistant root.
KPP: https://en.m.wikipedia.org/wiki/Kernel_Patch_Protection https://en.m.wikipedia.org/wiki/Kernel_Patch_Protection
SIP: https://en.m.wikipedia.org/wiki/System_Integrity_Protection https://en.m.wikipedia.org/wiki/System_Integrity_Protection