Language Selection

English French German Italian Portuguese Spanish

HookSafe Protects Kernel from Rootkits

Filed under
Linux
Security

The four researchers into the rootkit protector created and implemented a special virtualized system that defends against persistent rootkits that tamper with kernel execution. The system assembles specific function calls and messages, mirrors them in a "shadow interrupt stack" in a central location and protects them from hardware write access. To test their product, called HookSafe, the team let loose a few real rootkits and also measured the system load on the host system. The result showed just a 6% system slowdown, but with a highly effective implementation of the protection.

The team found successful defense against, for example, the Adore-ng and Phalanx rootkits. Xuxian Jiang, one of the four team members, told Linux Pro Magazine that the HookSafe source code will probably be made public sometime in the future.

Rest Here




More in Tux Machines

Today in Techrights

today's leftovers

Kernel Space: Linux, Graphics

Leftovers: Software

  • Introducing Stremio, a More Complete and Powerful Popcorn Time Alternative
    Stremio is an application built with Electron that streams and plays movies, TV shows, Youtube channels, and TV channels, from torrents. Sounds familiar?
  • mt-st project new homepage
    A short public notice: mt-st project new homepage at https://github.com/iustin/mt-st. Feel free to forward your distribution-specific patches for upstream integration!
  • letsencrypt support in propellor
    I'm using the reference letsencrypt client. While I've seen complaints that it has a lot of dependencies and is too complicated, it seemed to only need to pull in a few packages, and use only a few megabytes of disk space, and it has fewer options than ls does. So seems fine. (Although it would be nice to have some alternatives packaged in Debian.)
  • New release: usbguard-0.4
    I’m not dead yet. And the project is still alive too. It’s been a while since the last release, so it’s time to do another. The biggest improvements were made to the rule language by introducing the rule conditions and to the CLI by introducing a new command, usbguard, for interacting with a running USBGuard daemon instance and for generating initial policies.
  • The Improvements To GNOME's Nautilus 3.20 FIle Manager
  • Nautilus 3.20 Will Be a Major Upgrade, Here's What's New
    A new GNOME major upgrade is on its way, and it will ship with Nautilus 3.20. One of the developers working on it has presented some of the major features that will land.