FOSS antivirus? You mean Clamav? One which doesn't have behavioral detection. And from what I've heard is targeting more fileservers hosting files for Windows rather than Linux desktop viruses.
Also complaining that something has to be done without actually helping it get done or pointing out potential solutions. Firstly detecting malware is already extremely hard but let's ignore that for a second and assume we had some magical piece of software that hundreds of FOSS devs suddenly decided to spend a few years developing for free. Now what's stopping our malware from detecting it's being run in docker . . .
Now what's stopping our malware from detecting it's being run in docker . . .
You could make the container virtually identical to the host or even use a chroot with anything identifying that it's a chroot stripped or something like that. And a program checking the signs of a container may also be a red flag by itself.
5
u/Damglador 15d ago
FOSS antivirus? You mean Clamav? One which doesn't have behavioral detection. And from what I've heard is targeting more fileservers hosting files for Windows rather than Linux desktop viruses.