North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: IOS new architechture will be more vulnerable?

  • From: Valdis.Kletnieks
  • Date: Wed Aug 03 09:35:06 2005

On Wed, 03 Aug 2005 03:49:43 PDT, Aaron Glenn said:
> ...here's what the junior kernel hacker in me doesn't quite understand
> - doesn't software like ProPolice and it's brethren mitigate this type
> of vulnerability specifically? What, precisely, prevents Cisco from
> implementing such code in with their architecture?

"mitigate vulnerability" != "prevent vulnerability".

As long as it's a von Neumann architecture rather than a Harvard architecture,
there's potential issues.  Note that many mitigation strategies are basically
attempts to make it more Harvard-like....

Whether mitigation is sufficient is a topic for another list.. 

Attachment: pgp00001.pgp
Description: PGP signature