4 ms·
But why does a signature database update have to mess with the kernel in any kind of way? Shouldn't such a database stay in the user land?
by pyeri 2y ago
But why does a signature database update have to mess with the kernel in any kind of way? Shouldn't such a database stay in the user land?
- vbezhenar 2y agoBecause kernel needs to parse the data in some way and that parser apparently was broken enough. Whether it could be done in a more resilient manner, I don't know, you need to remember that antivirus works in hostile environment and can't necessarily trust userspace, so probably they need to verify signatures and parse payload in the kernel space.
- theshrike79 2y agoThe scanner is a Ring 0[0] program. Windows only has 2 options 0 and 3. 3 won't work for any kind of security scanners, so they're forced to use 0. The proper place would be Ring 1, which doesn't exist on Windows. And being a kernel-level operation, it has the capability to crash the whole system before the actual OS has any chance to intervene. [0] https://en.wikipedia.org/wiki/Protection_ring https://en.wikipedia.org/wiki/Protection_ring
- leosarev 2y agoWhy is so?
- hello_moto 2y agoThat's a question for Microsoft OS architects
- benchloftbrunch 2y agoHistorical reasons. Windows NT was designed to support architectures with only two privilege rings.
- layer8 2y agoAll modern OSes only use ring 0 and 3. Intel is considering removing rings 1 and 2 in a future revision for that reason: https://www.intel.com/content/www/us/en/developer/articles/technical/envisioning-future-simplified-architecture.html https://www.intel.com/content/www/us/en/developer/articles/t...