Hijacking the Linux Kernel

Authors Boris Prochazka, Tomas Vojnar, Martin Drahansky



PDF
Thumbnail PDF

File

OASIcs.MEMICS.2010.85.pdf
  • Filesize: 484 kB
  • 8 pages

Document Identifiers

Author Details

Boris Prochazka
Tomas Vojnar
Martin Drahansky

Cite As Get BibTex

Boris Prochazka, Tomas Vojnar, and Martin Drahansky. Hijacking the Linux Kernel. In Sixth Doctoral Workshop on Mathematical and Engineering Methods in Computer Science (MEMICS'10) -- Selected Papers. Open Access Series in Informatics (OASIcs), Volume 16, pp. 85-92, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2011) https://doi.org/10.4230/OASIcs.MEMICS.2010.85

Abstract

In this paper, a new method of hijacking the Linux kernel is presented. It is based on analysing the Linux system call handler, where a proper set of instructions is subsequently replaced by a jump to a different function. The ability to change the execution flow in the middle of an existing function represents a unique approach in Linux kernel hacking. The attack is applicable to all kernels from the 2.6 series on the Intel architecture. Due to this, rootkits based on this kind of technique represent a high risk for Linux administrators.

Subject Classification

Keywords
  • Linux kernel hacking
  • rootkit

Metrics

  • Access Statistics
  • Total Accesses (updated on a weekly basis)
    0
    PDF Downloads
Questions / Remarks / Feedback
X

Feedback for Dagstuhl Publishing


Thanks for your feedback!

Feedback submitted

Could not send message

Please try again later or send an E-mail