Language Selection

English French German Italian Portuguese Spanish

HookSafe Protects Kernel from Rootkits

Filed under
Linux
Security

The four researchers into the rootkit protector created and implemented a special virtualized system that defends against persistent rootkits that tamper with kernel execution. The system assembles specific function calls and messages, mirrors them in a "shadow interrupt stack" in a central location and protects them from hardware write access. To test their product, called HookSafe, the team let loose a few real rootkits and also measured the system load on the host system. The result showed just a 6% system slowdown, but with a highly effective implementation of the protection.

The team found successful defense against, for example, the Adore-ng and Phalanx rootkits. Xuxian Jiang, one of the four team members, told Linux Pro Magazine that the HookSafe source code will probably be made public sometime in the future.

Rest Here




More in Tux Machines

Google launches new site to showcase its open source projects and processes

Google is launching a new site today that brings all of the company’s open source projects under a single umbrella. The code of these projects will still live on GitHub and Google’s self-hosted git service, of course, with the new site functioning as a central directory for them. While this new project is obviously meant to showcase Google’s projects, the company says it also wants to use it to provide “a look under the hood” of how it “does” open source. Read more

Tizen and Android

Day of Infamy, CRYENGINE, and Performance Tools

Red Hat: We're giving VMware a 'run for its money' in virtualization

Red Hat's enterprise virtualization product is proving stiff competition for VMware, Paul Cormier, EVP and president of products and technologies, claimed at Red Hat's North American Partner Conference in Las Vegas, Nevada yesterday. According to the executive, Red Hat Virtualization (RHV), the open source software vendor's mission-critical, end-to-end open source virtualization infrastructure, has made a name for itself in such a way that VMware customers are increasingly showing interest in the technology. Read more Also: Red Hat CEO says businesses remain confident under Trump Amazon, Red Hat, Tesaro Price Targets Raised; Snap Started At Hold Tech Today: Snap’d By Facebook, Apple’s Innovation, Red Hat Jumps