Language Selection

English French German Italian Portuguese Spanish

HookSafe Protects Kernel from Rootkits

Filed under
Linux
Security

The four researchers into the rootkit protector created and implemented a special virtualized system that defends against persistent rootkits that tamper with kernel execution. The system assembles specific function calls and messages, mirrors them in a "shadow interrupt stack" in a central location and protects them from hardware write access. To test their product, called HookSafe, the team let loose a few real rootkits and also measured the system load on the host system. The result showed just a 6% system slowdown, but with a highly effective implementation of the protection.

The team found successful defense against, for example, the Adore-ng and Phalanx rootkits. Xuxian Jiang, one of the four team members, told Linux Pro Magazine that the HookSafe source code will probably be made public sometime in the future.

Rest Here




More in Tux Machines

India yet to catch up with FOSS, says Rushabh Mehta of ERPNext

We got a chance to interact with Rushabh Mehta, the founder of Web Notes Technologies, a company based in Mumbai, India. ERPNext is the major product of the company. It is a free and Open Source web based ERP (Enterprise Resource Planning) solution for small and medium sized businesses with its presence in more than 60 countries. In addition to the regular discussions on their Open Source product, strategy, customers etc. we also got a chance to understand how hard it is to thrive in an environment where the “Open Source” philosophy is not a familiar term yet. A software developer by passion and an Industrial Engineer by training, Rushabh also informed us about their imminent product conference in Mumbai he is quite excited about. Read more

Today in Techrights

Mesa 10.3 released

Mesa 10.3 has been released! Mesa 10.3 is a feature release that includes many updates and enhancements. The full list is available in the release notes file in docs/relnotes/10.3.html. The tag in the GIT repository for Mesa 10.3 is 'mesa-10.3'. I have verified that the tag is in the correct place in the tree. Mesa 10.3 is available for download at ftp://freedesktop.org/pub/mesa/10.3/ Read more

Tizen Development Units now available!

The Linux Foundation have today announced the next round of the Tizen development unit program is now available, with the Intel NUC and Samsung RD-PQ hardware devices being available. The Idea behind this program is to put the required hardware in developers hands so they can develop and test their applications on real hardware. It has to be noted that the Samsung RD-PQ device does not have GSM connectivity, and therefore can not be used as a real world device, which is a pity as developers do need real devices so late in the game. Read more