How to foil rootkits

How to foil rootkits

Put all your hooks in one basket.

Boffins from North Carolina State University have emerged from their smoke filled labs with a new way to block rootkits and prevent them from taking over your computer systems.

Rootkits are one of the nastiest forms of malware because they are hard to detect or remove.

Doctor Xuxian Jiang, assistant professor of computer science at NC State and a co-author of the research report said that hackers can use rootkits to install and hide spyware or other programs.

If your computer is compromised by a rootkit, it could mean that when you start your machine, everything seems normal but, unfortunately, your system is really owned by you anymore but by someone else.

The boffins were looking at the "hooks" that rootkits use control computer's operating system.

A rootkit takes control of these hooks to intercept and manipulate the computer system's data at will. It only lets the user see what it wants the user to see. As a result, the rootkit can make itself invisible not only to the computer user but also to antivirus software. It can also make other malware programs invisible as well.

Jiang and the other researchers looked at all of an operating system's hooks that need to be protected. This was tricky as an operating system might have thousands of hooks that could be used for a rootkit's purposes.

Jiang's research said that moving all the hooks to a centralised place makes them easier to manage and harder to subvert.

Once all the hooks were in one place the boffins could use hardware-based memory protection to prevent them from being hijacked.

The research with the catchy title "Countering Kernel Rootkits with Lightweight Hook Protection" will be presented at the 16th ACM Conference on Computer and Communications Security in Chicago on November 12.

Source: theinquirer.net (c) 2010 Incisive Media

See more about:  rootkits  |  security  |  drm
 
 
Latest articles on BIT Latest Articles from BIT
Federal Budget 2013: So what are you going to be required to pay?
15 May 2013
Opinion: Want a handy summary of the 2013 federal budget? Here is one by Newcastle accountants ...
Architects: another profession on the list of people using Evernote
10 May 2013
Yes, apparently the hugely popular Evernote note-syncing app is also being used by people who ...
In Brisbane? Setting up a business?
10 May 2013
Too embarrassed to ask even the most basic questions? Here's your chance to find out about ...
Worried about staff losing the office keys?
8 May 2013
Here's an interesting idea: a system which lets you assign a digital office "key" to your ...
Need a LOT more storage?
7 May 2013
Do you have multiple offices or servers? Are your systems requiring so much storage your IT ...

Latest Comments

Latest Competitions

Win a PC copy of DEFIANCE plus a Hellbug figurine and messenger bag! 

Win a PC copy of DEFIANCE plus a Hellbug figurine and messenger bag!

Win a Defiance prize pack and join the fight now!
 

Latest Poll

Which broadband network do you think is the best choice for Australia?



or View results
The Coalition's.
  19%
 
Labor's.
  63%
 
Screw this I'm going back to smoke signals and string on a can.
  19%
TOTAL VOTES: 1658

Vote now
Ads by Google

From our Partners

PC & Tech Authority Downloads