Research on Kernel Level Rootkit Technology Based on Linux System Call
Hanhui Huang
Abstract
Hanhui Huang
Abstract
System call is the interface between operating system and user's application.System call hijacking is a common technology used by kernel level Rootkit to attack operating system and keep backdoors.Research on the application of Linux system call mechanism and Linux system call hijacking in kernel level Rootkit can help to detect and protect Linux system from Rootkit.This paper analyzes the mechanism of Linux system call,and discusses the principle and implementation of how the kernel level Rootkit to hijacking Linux system call.Finally,three effective methods of detecting kernel level Rootkit are proposed.Based on these methods in the detecting process,it can improve the security of Linux system.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
System call is the interface between operating system and user's application.System call hijacking is a common technology used by kernel level Rootkit to attack operating system and keep backdoors.Research on the application of Linux system call mechanism and Linux system call hijacking in kernel level Rootkit can help to detect and protect Linux system from Rootkit.This paper analyzes the mechanism of Linux system call,and discusses the principle and implementation of how the kernel level Rootkit to hijacking Linux system call.Finally,three effective methods of detecting kernel level Rootkit are proposed.Based on these methods in the detecting process,it can improve the security of Linux system.
Key concepts: Rootkit, System call, Computer science, Operating system, Linux kernel, Kernel (algebra), Malware, Embedded system