JOURNAL ARTICLE

KLrtD: Kernel level rootkit detection

Abstract

Kernel rootkits pose a significant threat to computer systems as they run at the highest privilege level of operating system and have unrestricted access to the resources of their victims. Majority of current efforts in kernel rootkit defense focus on the detection of kernel rootkits. Various untrusted extensions, it remains a challenging problem to comprehensively preserve the integrity of OS kernels in a practical and generic way. In this regard, we propose a detection method named WHKrD that blocks and detects data kernel rootkit attacks by monitoring kernel data access using virtual machine monitor (VMM). WHKrD in inference mode, observe the execution of the kernel during an inference phase and extract white list rules on kernel data structures. In the following, integrity checker phase uses these rules as specifications of data structure integrity and any violation of rules indicates an infection. We have implemented a prototype of our system using the xen VMM. Our experiments show that it successfully detects data kernel rootkits, demonstrating its effectiveness and practicality.

Keywords:
Rootkit Computer science Kernel (algebra) Operating system Inference Malware Computer security Artificial intelligence

Metrics

2
Cited By
0.48
FWCI (Field Weighted Citation Impact)
32
Refs
0.75
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Security and Verification in Computing
Physical Sciences →  Computer Science →  Artificial Intelligence
Advanced Malware Detection Techniques
Physical Sciences →  Computer Science →  Signal Processing
Network Security and Intrusion Detection
Physical Sciences →  Computer Science →  Computer Networks and Communications

Related Documents

JOURNAL ARTICLE

Kernel-level hidden rootkit detection based on eBPF

Yun-Che YuChristina HungLi‐Der Chou

Journal:   Computers & Security Year: 2025 Vol: 157 Pages: 104582-104582
JOURNAL ARTICLE

Back to Static Analysis for Kernel-Level Rootkit Detection

Seyyedeh Atefeh MusaviMehdi Kharrazi

Journal:   IEEE Transactions on Information Forensics and Security Year: 2014 Vol: 9 (9)Pages: 1465-1476
JOURNAL ARTICLE

Advance Kernel Rootkit Detection: Survey

S Suresh KumarT. Sudalaimuthu

Year: 2023 Vol: 10 Pages: 944-948
BOOK-CHAPTER

RKRD: Runtime Kernel Rootkit Detection

Satyajit GroverHormuzd KhosraviDivya KolarSamuel MoffatMichael E. Kounavis

Communications in computer and information science Year: 2009 Pages: 224-236
JOURNAL ARTICLE

Drootkit: Kernel-Level Rootkit Detection and Recovery Based on eBPF

X. R. HuMing HuangYouhua XueLifeng JiangYao LiuGuoqi Xie

Journal:   Journal of Circuits Systems and Computers Year: 2023 Vol: 33 (04)
© 2026 ScienceGate Book Chapters — All rights reserved.