Abstract

The rootkit industry has advanced significantly in the last decade. Attackers want to leave a backdoor for quick reoccurring exploits rather than launching the traditional one-time worm/virus attacks. Meanwhile, as intrusion detection technologies improve, rootkits have grown in popularity. For the attackers to succeed, stealth becomes critical. The primary function of rootkits is to provide stealth. The modifications a rootkit makes conceal the presence of a rootkit. Determining the presence of mutation rootkits was quite challenging. Attackers can silently alter volatile (processes) and non-volatile (files) with the aid of rootkits without being noticed. We suggested the VKRHPDV (Volatile Kernel Rootkit Hidden Process Detection) framework to find the hidden techniques. This system includes process monitors, process comparison analysts, and contaminated process data gathering. Process monitoring is nothing more than clean process collection in the absence of rootkits, whereas pure process collection has been corrupted by rootkit injection. The process analyzer compares clean and tainted processes, some of which were concealed. VKRHPDV can identify process hiding behaviors in all datasets in the shortest period, according to the findings of an extensive performance analysis carried out on 64 rootkit datasets for each UNIX and Windows kernel in a cloud environment.

Details

Title
Volatile Kernel Rootkit hidden process detection in cloud computing
Author
S, Suresh Kumar 1 ; T, Sudalai Muthu 1 

 Hindustan Institute of Technology and Science, Department of Computer Science and Engineering, Chennai, India (GRID:grid.444645.3) (ISNI:0000 0001 2358 027X) 
Pages
164
Publication year
2023
Publication date
Dec 2023
Publisher
Springer Nature B.V.
e-ISSN
2192113X
Source type
Scholarly Journal
Language of publication
English
ProQuest document ID
2893474786
Copyright
© The Author(s) 2023. This work is published under http://creativecommons.org/licenses/by/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.