...
首页> 外文期刊>IEEE security & privacy >Detecting and categorizing kernel-level rootkits to aid future detection
【24h】

Detecting and categorizing kernel-level rootkits to aid future detection

机译:对内核级rootkit进行检测和分类以帮助将来进行检测

获取原文
获取原文并翻译 | 示例
           

摘要

Existing techniques to detect kernel-level rootkits expose some infections, but they don't identify specific attacks. This rootkit categorization approach helps system administrators identify the extent of specific infections, aiding in optimal recovery and faster reactions to future attacks. The authors present a framework to detect and classify rootkits and discuss a methodology for determining if a system has been infected by a kernel-level rootkit. Once infection is established, administrators can create new signatures for kernel-level rootkits to detect them. The authors conducted their research on a Red Hat Linux-based system, but the methodology is applicable to other Linux distributions based on the standard Linux kernel. They also believe the method can apply to other Unix- and Windows-based systems.
机译:现有的检测内核级rootkit的技术会暴露一些感染,但它们无法识别特定的攻击。这种rootkit归类方法可帮助系统管理员确定特定感染的程度,从而有助于最佳恢复和对未来攻击的更快反应。作者提出了一种检测和分类Rootkit的框架,并讨论了确定系统是否已被内核级Rootkit感染的方法。建立感染后,管理员可以为内核级rootkit创建新的签名来检测它们。作者在基于Red Hat Linux的系统上进行了研究,但是该方法适用于基于标准Linux内核的其他Linux发行版。他们还认为该方法可以应用于其他基于Unix和Windows的系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号