The research on rootkit for information system classified protection

Zhihong Tian, Bailing Wang, Zixi Zhou, Hongli Zhang · 2011

Base on the analysis of linux system execution path, rootkits are divided into two categories, rootkit based on system call hook and rootkit based on system exception hook. According to the different stages of system call, system call hook included preload library, simple sys_call_table hook, inline system call hook, patch system_call hook, Rootkit based on /dev/kmem and/dev/mem. System exception hook rootkits include two exception exploit, abuse debug registers and hijack linux page fault handler.

Read the paper · More papers on PaperTik