This article addresses the significant threat posed by rootkits as part of the diverse malware landscape of today. Rootkits enable an attacker to regain access to an already comprised system at root-level making their prompt identification and removal crucial. However, rootkits implement advanced stealth features, enabling them to evade detection by conventional measures during analysis. Consequently, analysts generally rely on customized tools to detect the presence of a rootkit. However, our research highlights significant deficits in the tools available for the detection of rootkits on the Linux operating system, which is frequently encountered in investigations of server environments. Recognizing the need for improved awareness and capabilities among investigators, we conducted an in-depth analysis of 21 distinct Linux rootkits allowing us to dive into their techniques and features. Furthermore, we critically assessed the effectiveness of standard detection tools, revealing their limitations. Based on these insights, we propose best practices for investigators to effectively identify and detect signs of rootkit infections. Additionally, we provide a repository of indicators of compromise we extracted during our analyses to facilitate the detection of the analyzed rootkits on compromised systems along with a utility to detect rootkits via hidden files on a live system.
机构:
Hangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R ChinaHangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R China
Jin, Meiqing
Liu, Jinsong
论文数: 0引用数: 0
h-index: 0
机构:
Zhejiang Ecol & Environm Monitoring Ctr, Zhejiang Key Lab Ecol & Environm Monitoring Forewa, Hangzhou, Peoples R China
Zhejiang Ecol & Environm Monitoring Ctr, Zhejiang Key Lab Ecol & Environm Monitoring Forewa, Hangzhou 310012, Peoples R ChinaHangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R China
Liu, Jinsong
Yu, Jie
论文数: 0引用数: 0
h-index: 0
机构:
China Jiliang Univ, Dept Environm Engn, Hangzhou, Peoples R ChinaHangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R China
Yu, Jie
Zhou, Qingwei
论文数: 0引用数: 0
h-index: 0
机构:
Hangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R ChinaHangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R China
Zhou, Qingwei
Wu, Weihong
论文数: 0引用数: 0
h-index: 0
机构:
Hangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R ChinaHangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R China
Wu, Weihong
Fu, Li
论文数: 0引用数: 0
h-index: 0
机构:
Hangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R ChinaHangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R China
Fu, Li
Yin, Chengliang
论文数: 0引用数: 0
h-index: 0
机构:
Chinese Peoples Liberat Army Gen Hosp, Natl Engn Lab Med Big Data Applicat Technol, Beijing, Peoples R China
Peoples Liberat Army Gen Hosp, Med Big Data Res Ctr, Med Innovat Res Div, Beijing, Peoples R ChinaHangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R China
Yin, Chengliang
Fernandez, Carlos
论文数: 0引用数: 0
h-index: 0
机构:
Robert Gordon Univ, Sch Pharm & Life Sci, Aberdeen, ScotlandHangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R China
Fernandez, Carlos
Karimi-Maleh, Hassan
论文数: 0引用数: 0
h-index: 0
机构:
Univ Elect Sci & Technol China, Sch Resources & Environm, Chengdu, Peoples R China
Quchan Univ Technol, Dept Chem Engn, Quchan, Iran
Univ Johannesburg, Dept Chem Sci, Johannesburg, South AfricaHangzhou Dianzi Univ, Coll Mat & Environm Engn, Hangzhou, Peoples R China