UNIX and Linux based Rootkits Techniques and Countermeasures

Andreas Bunten · 2004

A rootkit enables an attacker to stay unnoticed on a compromised system and to use it for his purposes. This paper reviews techniques currently used by attackers on UNIX and Linux systems with a focus on kernel rootkits. Example rootkits are classied according to code injection and how the ow of execution is diverted within the kernel. The efciency of different countermeasures is discussed for these examples.

Read the paper · More papers on PaperTik