4 ms·
Even with the actual hook logic running on the CPU, this prevents a large amount of possible detection from various filesystem/workingmem vectors...
by hnspirit 7y ago
Even with the actual hook logic running on the CPU, this prevents a large amount of possible detection from various filesystem/workingmem vectors...
- badrabbit 7y agoAnd forensic analysis too. I think lack of existing tools that analyze and protect GPU based anomalies is what this project highlights.
- theamk 7y agoBut the hook's .so file still has to be loaded from filesystem, so it should be still detectable? And even if "hook logic" runs on the GPU, the actual function calls still have plenty of CPU parts. Check out rootkit/kit.c -- it is just plain old LD_PRELOAD rootkit, with a ton of calls running on CPU. Workingmem detector should have no problems matching this code.