Mitigation Techniques

Reviewed mitigation technologies we should consider and attempted to decide if we should put effort into implementation.

W^X

noexec stack

CFI

ASLR

KASLR

SafeStack

SW PAN emulation (UDREF)

PAN, SMAP

PXN, SMEP

Live patching

Refcount type / saturating or panic reference count

Mitigation control, deployment

TODOs

DevSummit/201708/Security_mitigation (last edited 2018-04-01T00:59:34+0000 by MarkLinimon)