ISC StormCast for Thursday, December 21st 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 21 December 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, December 21st, 2017 edition of the Sansonet Storm Center's |
| 0:07.0 | Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
| 0:13.0 | One of the most basic and foundational parts of any operating systems, be it Windows or Unix, is the kernel. |
| 0:22.6 | Now, a matter of course tries to modify and hide itself from the kernel because if it can |
| 0:29.6 | accomplish that, it makes it a lot more difficult to detect and remove. |
| 0:35.6 | And if you are interested in how this all works, how attackers get access to the kernel, |
| 0:41.3 | how you may be able to detect it, we do have a great guest diary today by Itaigneur. |
| 0:48.3 | Pretty long read compared to some of our other diaries, but certainly worthwhile for you to go over it. Maybe, just maybe, |
| 0:57.6 | it's a little bit slower at work today, so that may be ideal to take a step at learning |
| 1:03.9 | something like how kernel hooking works. And one of the up-and-coming security technologies is memory encryption. |
| 1:12.6 | Now, we long have had full disk encryption. |
| 1:16.9 | Memory encryption has been tricky for a number of reasons. |
| 1:20.8 | First of all, performance, of course, could suffer, which is particular critical for memory. |
| 1:27.0 | And then also, how do you store keys |
| 1:29.0 | and how meaningful is it to actually encrypt memory? Well, Intel now published their take on the |
| 1:36.7 | problem with a new specification for total memory encryption. One interesting feature here is that the memory can actually be |
| 1:46.7 | segmented into different encrypted parts. This is of course particularly interesting for |
| 1:53.1 | virtualization where you can add an additional barrier here between memory used by |
| 1:59.0 | different virtual machines by encrypting it using different keys. |
| 2:05.2 | AMV is also working on a similar technology that has already been deployed in some of its |
| 2:12.0 | processors and Linux actually just started supporting this technology on a virtual machine level. |
| 2:20.3 | So with this you can encrypt memory for each virtual machine individually, which actually not only |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

