Skip to main navigation Skip to search Skip to main content

RBACS: Rootkit Behavioral Analysis and Classification System

Desmond Lobo*, Paul Watters, Xinwen Wu

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

Abstract

In this paper, we focus on rootkits, a special type of malicious software (malware) that operates in an obfuscated and stealthy mode to evade detection. Categorizing these rootkits will help in detecting future attacks against the business community. We first developed a theoretical framework for classifying rootkits. Based on our theoretical framework, we then proposed a new rootkit classification system and tested our system on a sample of rootkits that use inline function hooking. Our experimental results showed that our system could successfully categorize the sample using unsupervised clustering.

Original languageEnglish
Title of host publicationProceedings: Third International Conference on Knowledge Discovery and Data Mining
EditorsMingmin Gong, Qi Luo
Place of PublicationPiscataway, USA
PublisherInstitute of Electrical and Electronics Engineers (IEEE)
Pages75-80
Number of pages6
ISBN (Print)9780769539232
DOIs
Publication statusPublished - 2010
Externally publishedYes
Event3rd International Conference on Knowledge Discovery and Data Mining, WKDD 2010 - Phuket, Thailand
Duration: 9 Jan 201010 Jan 2010

Conference

Conference3rd International Conference on Knowledge Discovery and Data Mining, WKDD 2010
Country/TerritoryThailand
CityPhuket
Period9/01/1010/01/10

Keywords

  • Behavioral analysis
  • Classification
  • Data mining
  • Malware
  • Rootkits

Fingerprint

Dive into the research topics of 'RBACS: Rootkit Behavioral Analysis and Classification System'. Together they form a unique fingerprint.

Cite this