N
N
numitus2013-03-01 00:50:29
Antivirus
numitus, 2013-03-01 00:50:29

Can antivirus sandboxes isolate driver code?

Can antivirus sandboxes isolate driver code?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
@
@ntkt, 2013-03-01
@numitus

No. There is no mention of isolation.
Theoretically, this is possible, but it will be slow, unstable and unprofitable.
Fighting at the same level of privilege with the enemy, security tools always lose. If the malicious code is already in ring0, it's gone.
The solution is to go down a level and put security in the hypervisor. But that's a completely different story.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question