Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <0215ebaf-e475-b2f6-23a7-beb8aefa4fc2@gmail.com>
Date: Fri, 19 Jun 2020 14:53:57 +0200
From: Mikhail Morfikov <mmorfikov@...il.com>
To: lkrg-users@...ts.openwall.com
Subject: Re: rootkit detection

On 14/06/2020 17:37, Solar Designer wrote:
> Hi,
> 
> Adam found this interesting Master's Thesis of Juho Junnila, entitled
> "Effectiveness of Linux Rootkit Detection Tools":
> 
> http://jultika.oulu.fi/files/nbnfioulu-202004201485.pdf
> 

I'm in the middle of reading the pdf, and I have one question. Since all the 
kernel rootkits described in the paper are provided in the form of external 
LKMs, is there a way to include LKRG source in the kernel source tree somehow?
In this way when the kernel is built, the module would also be compiled as a 
regular module, or compiled into the kernel itself. Is this doable?




Download attachment "signature.asc" of type "application/pgp-signature" (229 bytes)

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.