Abstract
In this paper, we focus on rootkits, a special type of malicious software (malware) that operates in an obfuscated and stealthy mode to evade detection. Categorizing these rootkits will help in detecting future attacks against the business community. We first developed a theoretical framework for classifying rootkits. Based on our theoretical framework, we then proposed a new rootkit classification system and tested our system on a sample of rootkits that use inline function hooking. Our experimental results showed that our system could successfully categorize the sample using unsupervised clustering.
| Original language | English |
|---|---|
| Title of host publication | Proceedings: Third International Conference on Knowledge Discovery and Data Mining |
| Editors | Mingmin Gong, Qi Luo |
| Place of Publication | Piscataway, USA |
| Publisher | Institute of Electrical and Electronics Engineers (IEEE) |
| Pages | 75-80 |
| Number of pages | 6 |
| ISBN (Print) | 9780769539232 |
| DOIs | |
| Publication status | Published - 2010 |
| Externally published | Yes |
| Event | 3rd International Conference on Knowledge Discovery and Data Mining, WKDD 2010 - Phuket, Thailand Duration: 9 Jan 2010 → 10 Jan 2010 |
Conference
| Conference | 3rd International Conference on Knowledge Discovery and Data Mining, WKDD 2010 |
|---|---|
| Country/Territory | Thailand |
| City | Phuket |
| Period | 9/01/10 → 10/01/10 |
Keywords
- Behavioral analysis
- Classification
- Data mining
- Malware
- Rootkits
Fingerprint
Dive into the research topics of 'RBACS: Rootkit Behavioral Analysis and Classification System'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver