Language Selection

English French German Italian Portuguese Spanish

HookSafe Protects Kernel from Rootkits

Filed under
Linux
Security

The four researchers into the rootkit protector created and implemented a special virtualized system that defends against persistent rootkits that tamper with kernel execution. The system assembles specific function calls and messages, mirrors them in a "shadow interrupt stack" in a central location and protects them from hardware write access. To test their product, called HookSafe, the team let loose a few real rootkits and also measured the system load on the host system. The result showed just a 6% system slowdown, but with a highly effective implementation of the protection.

The team found successful defense against, for example, the Adore-ng and Phalanx rootkits. Xuxian Jiang, one of the four team members, told Linux Pro Magazine that the HookSafe source code will probably be made public sometime in the future.

Rest Here




More in Tux Machines

Radeon Linux Gaming Performance: Ubuntu 17.04 vs. Ubuntu 17.10

With Ubuntu 17.10 set to ship tomorrow that features just not an upgraded Linux kernel and Mesa 3D stack but also transitions from Unity 7 + X.Org to GNOME Shell + Wayland, here are some comparison gaming benchmarks on a few different AMD Radeon graphics cards. Ubuntu 17.04 shipped six months ago with Linux 4.10 and Mesa 17.0.7 as the main graphics components for open-source driver users while now with Ubuntu 17.10 is the Linux 4.13 kernel and Mesa 17.2.2. The six months of improvements to Mesa alone are massive for Intel and Radeon users with the RADV/ANV Vulkan drivers maturing much over this time (17.10 still doesn't ship with the Vulkan drivers, but are just a sudo apt install mesa-vulkan-drivers away) as well as many performance improvements and new extensions for the growing number of bundled OpenGL drivers. If you read Phoronix daily, you should already be well versed on the many Mesa accomplishments over this time span. Read more

Linux on Galaxy is Samsung's most impressive DeX app yet

Alongside the Galaxy S8/S8+, Samsung also introduced DeX to the world this past February. DeX is Samsung's vision for the future of desktop computing, and while it still has a way to go before it's truly useful or practical for everyone, Linux on Galaxy is a new app that Samsung hopes will make DeX more appealing to developers. Samsung announced Linux on Galaxy at its developer conference on October 18, and although the app is still in a trial phase, it already sounds pretty impressive. Read more Also: Samsung unveils 'Linux on Galaxy' for DeX -- run Fedora and Ubuntu on your Note8?

Skylake embedded computer has a thin 1U profile

Advantech has expanded its line of fanless, barebone EPC computers with a 43mm high “EPC-T1232” system based on a Skylake U-series thin Mini-ITX board. In August, Advantech launched its Linux-ready AIMB-232 thin Mini-ITX SBC featuring 6th Gen “Skylake” U-Series CPUs. Now it has followed up with an EPC-T1232 barebone computer based on the SBC, or specifically, the AIMB-T12325W-00Y0E model. Like the SBC, the EPC-T1232 has a low profile, measuring 250 x 210 x 43mm. Read more

today's leftovers