GrapheneOS-Archive / legacy_bugtracker

See the new issue tracker for GrapheneOS at https://github.com/GrapheneOS/os_issue_tracker.
112 stars 11 forks source link

IDS #243

Closed thestinger closed 7 years ago

thestinger commented 8 years ago

It would be cool to have optional built-in IDS support. It's not possible to do this well without it being built into the OS due to lack of privileges, especially as the app sandbox is hardened. It's an area where CopperheadOS could provide a real edge. Android has SafetyNet, but that's meant to protect the ecosystem as a whole, not individuals.

xmikos commented 8 years ago

It would be great if it could also detect QUANTUM INSERT attacks, see here: Deep dive into QUANTUM INSERT (configuration for Bro, Snort and Suricata IDS here: https://github.com/fox-it/quantuminsert/tree/master/detection).

Not only NSA, but now even Chinese, Malaysian and Indian malware and ad networks seems to be doing QUANTUMINSERT-style man-on-the-side attacks: Website-Targeted False Content Injection by Network Operators

thestinger commented 7 years ago

Not planned.

thestinger commented 6 years ago

This is going to be revived as part of our Auditor app: https://github.com/copperhead/Auditor/issues/27.