Vis enkel innførsel

dc.contributor.advisorNygård, Madsnb_NO
dc.contributor.advisorWeng, Ane Daaenb_NO
dc.contributor.authorMelcher, Tobiasnb_NO
dc.date.accessioned2014-12-19T13:33:05Z
dc.date.available2014-12-19T13:33:05Z
dc.date.created2010-09-03nb_NO
dc.date.issued2005nb_NO
dc.identifier348095nb_NO
dc.identifierntnudaim:1038nb_NO
dc.identifier.urihttp://hdl.handle.net/11250/250964
dc.description.abstractKernel-mode rootkits represent a considerable threat to any computer system, as they provide an intruder with the ability to hide the presence of his malicious activity. These rootkits make changes to the operating system s kernel, thereby providing particularly stealthy hiding techniques. This thesis addresses the problem of collecting reliable information from a system compromised by kernel-mode rootkits. It looks at the possibility of using virtualization as a means to facilitate kernel-mode rootkit detection through integrity checking. It describes several areas within the Linux kernel, which are commonly subverted by kernel-mode rootkits. Further, it introduces the reader to the concept of virtualization, before the kernel-mode rootkit threat is addressed through a description of their hiding methodologies. Some of the existing methods for malware detection are also described and analysed. A number of general requirements, which need to be satisfied by a general model enabling kernel-mode rootkit detection, are identified. A model addressing these requirements is suggested, and a framework implementing the model is set-up.nb_NO
dc.languageengnb_NO
dc.publisherInstitutt for datateknikk og informasjonsvitenskapnb_NO
dc.subjectntnudaimno_NO
dc.subjectSIF2 datateknikkno_NO
dc.subjectProgram- og informasjonssystemerno_NO
dc.titleIntegrity checking of operating systems with respect to kernel level malwarenb_NO
dc.typeMaster thesisnb_NO
dc.source.pagenumber141nb_NO
dc.contributor.departmentNorges teknisk-naturvitenskapelige universitet, Fakultet for informasjonsteknologi, matematikk og elektroteknikk, Institutt for datateknikk og informasjonsvitenskapnb_NO


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel