Prevention of Kernel Rootkit in Cloud Computing

S Suresh Kumar, A Ponni Valavan, V Prathiksha · 2023

A rootkit is a malicious programme created to load and operate directly from the operating system kernel. Kernel-mode rootkits, also referred to as rootkits that operate in the kernel, have the power to change the operating system as a whole. Such changes to the kernel are intended to hide the hack As a result, it is quite challenging to find a kernel rootkit. A system’s kernel can be modified via a variety of methods. Kernel rootkits also produce backdoor access, giving hackers covert access to the system. As a result, hackers have the capacity to change important computer data, collect personal information, and observe behaviour. Artificial neural networks provide support for the machine learning subfield known as deep neural network which is alike human brain mimic that works on massive datasets. In this work, the kernel rootkit is identified from the provided dataset using deep learning techniques by choosing the crucial features for training the detection models. Therefore, rootkit attacks can be prevented from downloading the affected files by identifying the kernel rootkit which is tested in AWS cloud environment by hosting the model in the EC2 instance. The unique feature of this work is how it utilizes the hyper-parameter tuning to enhance accuracy results.

Read the paper · More papers on PaperTik