K-Tracer: A System for Extracting Kernel Malware Behavior.
Andrea Lanzi, Monirul I. Sharif, Wenke Lee · 2009
Kernel rootkits can provide user level-malware programs with the additional capabilities of hiding their malicious ac-tivities by altering the legitimate kernel behavior of an op-erating system. While existing research has studied rootkit hooking behavior in an effort to help develop defense and remediation mechanisms, automated analysis of the actual malicious goals and capabilities of rootkits has not been adequately investigated. In this paper, we present an ap-proach based on a combination of backward slicing and chopping techniques that enables automatic discovery of the system data manipulation behaviors of rootkits. We have built a system called K-Tracer that can dynamically analyze Windows kernel-level code and extract malicious behaviors from rootkits, including sensitive data access, modification and triggers. Our system overcomes several challenges of analyzing the Windows Kernel. We have performed exper-iments on several kernel malware samples and shown that our system can successfully extract all malicious data ma-nipulation behaviors from them. We also discuss the limita-tions of our current system on newer rootkit strategies, and provide insight into how it can be extended to handle these emerging threats. 1