ModuleJail për bllokimin e moduleve të papërdorura të bërthamës Linux

Jasper Nuyens, the founder of Linux Belgium, who created an extension for using Linux in Tesla's automotive information system, proposed a simple way to reduce the attack surface of the Linux kernel to lower the likelihood of compromise amid a surge in the discovery of dangerous vulnerabilities using AI. Since many vulnerabilities are often found in specific kernel modules that are autoloaded but typically not used by most users, Jasper suggested blocking, by default, the modules that are not used in the current system or are generally rarely utilized.

There are several thousand modules available in the kernel, but only a few hundred are typically used in most systems, while the rest remain available for loading and could potentially contain vulnerabilities. The idea is implemented via a script called ModuleJail, which determines the list of modules used in the current system (via /proc/modules) and automatically blacklists unused modules. The script is written in shell, utilizes common system utilities (enough busybox), and is distributed under the GPLv3 license.

Skrypti mbështet ekzekutimin në Debian, Ubuntu, RHEL, Fedora, SUSE, AlmaLinux, Rocky Linux, Alpine dhe Arch Linux, dhe si rezultat i punës së tij gjeneron skedarin /etc/modprobe.d/modulejail-blacklist.conf, i cili përdoret zakonisht në sistem për të çaktivizuar ngarkimin e automatizuar të moduleve të bërthamës. Ky qasje lejon mbrojtjen preventive të sistemit tuaj, pa pasur nevojë për ngarkimin e moduleve të specializuara të bërthamës ose për ekzekutimin e proceseve të shtesë në sfond për monitorim.

Nëse është e nevojshme, përdoruesit i jepet mundësia për të shtuar në listën e bardhë modulet, të cilat në këtë moment nuk janë ngarkuar, por potencialisht mund të përdoren në punë. Gjithashtu, janë të disponueshme për aktivizim profile që lejojnë përdorimin e moduleve më të nevojshme për aplikacionet tipike të sistemit. Profilat e propozuara janë "minimal" (vetëm modulet më të rëndësishme dhe sistemet e skedarëve bazë), "konservatore" (+ drejtuesit tipikë për serverët dhe makinave virtuale) dhe desktop (+ drejtuesit për WiFi, Bluetooth, zvuk dhe video).

Burimi: opennet.ru

Bli njĂ« hosting tĂ« besueshĂ«m pĂ«r faqet me mbrojtje DDoS, VPS VDS serverĂ« đŸ”„ Bli njĂ« hosting tĂ« besueshĂ«m pĂ«r faqet me mbrojtje DDoS, VPS VDS serverĂ« | ProHoster