skip to main content
10.1145/1409908.1409916acmotherconferencesArticle/Chapter ViewAbstractPublication PagesinfoseccdConference Proceedingsconference-collections
research-article

An undergraduate rootkit research project: How available? How hard? How dangerous?

Published:28 September 2007Publication History

ABSTRACT

A rootkit is a small, hard to detect computer program that stealthily invades an operating system or kernel and takes control of the computer. The rootkit can be placed on a computer by a hacker that gains unauthorized access to a computer, or by an unsuspecting authorized user that allows a virus or other malicious software to insert the rootkit into their computer. Cyberspace is full of threats and risks. Each danger must be carefully considered and protected against only to the extent that is reasonable and affordable in accordance with a prudent risk management program. When considering rootkits a risk manager will ask: How common are they? How severe are the consequences? How can they be prevented? How can they be removed? These general questions have been explored in a number of research projects and publications. At a finer level of detail and on a recurring basis, information assurance managers will also ask 'as of right now': How hard are they to create? How available is rootkit source code? How hard are they to install and operate? This paper describes a research project at Murray State University in which faculty and senior undergraduate students explored this second set of more time-sensitive questions. It describes both the pedagogical and technical issues of having students find rootkit source code on the web; getting the source code to run and operate in an academic laboratory without threatening the university's IT environment; and exploring what tools and techniques are currently available for detecting and removing rootkits.

References

  1. Huglund and Butler, Rootkits, Subverting the Windows Kernel, Addison Wesley, 2005. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Prevlakis and Spinellis, The Athens Affair, IEEE Spectrum, July 2007, volume 44 number 7, p 26--33. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. Schneir, Sony's DRM Rootkit: The Real Story, Wired, November 17, 2005. http://www.schneier.com/blog/archives/2005/11/sonys_drm_rootk.html, accessed on 8/24/2007Google ScholarGoogle Scholar
  4. Skoudis, Malware: Fighting Malicious Code, Prentice Hall, 2004. Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. http://packetstorm.linuxsecurity.com accessed on 8/24/2007.Google ScholarGoogle Scholar
  6. http://sourceforge.net accessed on 8/24/2007Google ScholarGoogle Scholar
  7. http://rootkits.com accessed on 8/24/2007Google ScholarGoogle Scholar
  8. http://www.emsisoft.com accessed 8/24/200Google ScholarGoogle Scholar

Index Terms

  1. An undergraduate rootkit research project: How available? How hard? How dangerous?

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Other conferences
      InfoSecCD '07: Proceedings of the 4th annual conference on Information security curriculum development
      September 2007
      157 pages
      ISBN:9781595939098
      DOI:10.1145/1409908

      Copyright © 2007 ACM

      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 28 September 2007

      Permissions

      Request permissions about this article.

      Request Permissions

      Check for updates

      Qualifiers

      • research-article

      Acceptance Rates

      Overall Acceptance Rate18of23submissions,78%

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader