A Methodology to Detect Kernel Level Rootkits based on Detecting Hidden Processes

Jie Hao, Yu‐Jie Hao, Zhi-Jian Ding, Lin-Tao Song · 2008

Intruders will normally install some tools when he gains access to a computer system, in order to regain the root privilege when he come back onto the system at a later time. Installing a rookit on the compromised system is one of the methods that a intruder may use. The kernel of the operating system which is the lowest level of most modern OS will be modified by a kernel level rootkit. In this paper we present a standardized methodology to detect rootkits. Through this method, it is possible to provide additional protection against this type of malicious modification of the kernel.

Read the paper · More papers on PaperTik