Rootkits (Part 8): Defense via Hook Detection
Sourcefire
0:00 / 0:00
Rootkits (Part 8): Defense via Hook Detection
2 811 просмотров · 13 лет назад
Sourcefire
8,65 тыс. подписчиков
2 811 просмотров · 13 лет назад
Since both kernel-mode and user-mode rootkits use hooking as a vehicle for hiding their presence on a system, it seems only natural that looking for system hooks could itself be used to identify the presence of a rootkit on a system. In this video, Sourcefire Chief Scientist, Zulfikar Ramzan, describes how one might try to make such a rootkit detection technique work and what challenges exist in doing so. This video is the eighth in a multi-part series on rootkits. For a comprehensive list of chalk talks, please visit http://sourcefire.com/chalktalks