Please use this identifier to cite or link to this item: http://repository.futminna.edu.ng:8080/jspui/handle/123456789/11636
Title: Evaluating Capabilities Of Rootkits Tools
Authors: Subairu, Sikiru
Alhassan, John
Sanjay, Misra
Keywords: Rootkits, infection, detectors, detection, network scanning,
Issue Date: Nov-2016
Publisher: International Journal of Advanced Multidisciplinary Research and Studies (IJAMRS)
Citation: http://www.ijamrs.in
Abstract: Rootkit is a fatal malware devouring user and kernel mode kind which inclines to take complete control of a compromised system by means of various infection and evasion techniques. Several detection algorithms has been offered and joined into the anti rootkit tools with many degree of performance in handling rootkit incidence. There is a severe rise in the rootkit attack with irregular rootkit samples such as, zeroaccess, darkmegi, tdl-4 and xpaj.mbr with each one having different impact on the internal structure of an operating system. Therefore, in this study analysis of rootkits tools were carried out using active detectors tools and malware forensic analysis tools, applying system scanning, network scanning and malware forensic analysis methodology. Altogether the samples rootkit have one or more rootkit detectors to handle their incidence though at a varied performance rate except darkmegi. Though two of the detectors were able to detect its presence on a compromised system, but failed in removal attempt.
URI: http://repository.futminna.edu.ng:8080/jspui/handle/123456789/11636
Appears in Collections:Cyber Security Science

Files in This Item:
File Description SizeFormat 
JournalJKASubairuandMisra.pdf394.85 kBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.