RBACS: Rootkit Behavioral Analysis and Classification System

File Size Format
68262_1.pdf 330Kb Adobe PDF View
Title RBACS: Rootkit Behavioral Analysis and Classification System
Author Lobo, Desmond; Watters, Paul; Wu, Xin-Wen
Publication Title Proceedings Third International Conference on Knowledge Discovery and Data Mining WKDD 2010
Editor Mingmin Gong, Qi Luo
Year Published 2010
Place of publication Los Alamitos
Publisher IEEE
Abstract In this paper, we focus on rootkits, a special type of malicious software (malware) that operates in an obfuscated and stealthy mode to evade detection. Categorizing these rootkits will help in detecting future attacks against the business community. We first developed a theoretical framework for classifying rootkits. Based on our theoretical framework, we then proposed a new rootkit classification system and tested our system on a sample of rootkits that use inline function hooking. Our experimental results showed that our system could successfully categorize the sample using unsupervised clustering.
Peer Reviewed Yes
Published Yes
Publisher URI http://www.iita-conference.org/wkdd2010/
Alternative URI http://dx.doi.org/10.1109/WKDD.2010.23
Copyright Statement Copyright 2010 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.
ISBN 978-1-4244-5397-9
Conference name 3rd International Conference on Knowledge Discovery and Data Mining (WKDD 2010)
Location Phuket, Thailand
Date From 2010-01-08
Date To 2010-01-11
URI http://hdl.handle.net/10072/37756
Date Accessioned 2011-02-10
Language en_US
Research Centre Institute for Integrated and Intelligent Systems
Faculty Faculty of Science, Environment, Engineering and Technology
Subject Information Systems
WWW reference http://www.iita-conference.org/wkdd2010/
Publication Type Conference Publications (Full Written Paper - Refereed)
Publication Type Code e1x

Show simple item record

Griffith University copyright notice