A method for identifying hidden information leak channels due to incorrect updates of database management system kernel programs

Software security
Authors:
Abstract:

This article examines the problem of vulnerabilities that arise during software updates in isolated corporate systems running Astra Linux. A possible method for implementing an attack to gain root access through a modified software update package is demonstrated. A multi-layered method for detecting update package modifications is proposed, including static, behavioral, and signature-based analysis using machine learning methods and algorithms. This method significantly improves the security of the software update process in network isolation.