Rootkit attacks and protection: a case study of teaching network security

Thomas M. Arnold, T. Andrew Yang · Journal of computing sciences in colleges · 2011

A rootkit is a type of malware designed to gain privileged access to a computer while hiding itself from the user and the operating system by, for example, compromising the communication channels within the OS. A rootkit can hide files, data, processes, and network ports, and can typically survive a system restart. This stealthy design enables the rootkit to escape detection by most anti-malware tools, which may be effective in detecting/removing malware like viruses but are generally ineffective against rootkits. To answer this challenge, special anti-rootkit software applications have been developed. In this paper, we first review the status quo of Windows-based rootkits and anti-rootkit software. We then discuss how rootkits may be incorporated into classes to teach computer and network security concepts.

Read the paper · More papers on PaperTik