Hooks hijacked? New research shows how to block stealthy malware attacks

November 3, 2009

The spread of malicious software, also known as malware or computer viruses, is a growing problem that can lead to crashed computer systems, stolen personal information, and billions of dollars in lost productivity every year. One of the most insidious types of malware is a "rootkit," which can effectively hide the presence of other spyware or viruses from the user - allowing third parties to steal information from your computer without your knowledge. But now researchers from North Carolina State University have devised a new way to block rootkits and prevent them from taking over your computer systems.

To give some idea of the scale of the malware problem, a recent Internet security threat report showed a 1,000 percent increase in the number of new malware signatures extracted from the in-the-wild malware programs found from 2006 to 2008. Of these malware programs, "rootkits are one of the stealthiest," says Dr. Xuxian Jiang, assistant professor of at NC State and a co-author of the research. "Hackers can use rootkits to install and hide spyware or other programs. When you start your machine, everything seems normal but, unfortunately, you've been compromised."

Rootkits typically work by hijacking a number of "hooks," or control data, in a computer's operating system. "By taking control of these hooks, the rootkit can intercept and manipulate the computer system's data at will," Jiang says, "essentially letting the user see only what it wants the user to see." As a result, the rootkit can make itself invisible to the computer user and any antivirus software. Furthermore, the rootkit can install additional , such as programs designed to steal personal information, and make them invisible as well.

In order to prevent a rootkit from insinuating itself into an operating system, Jiang and the other researchers determined that all of an operating system's hooks need to be protected. "The challenging part is that an may have tens of thousands of hooks - any of which could potentially be exploited for a rootkit's purposes," Jiang says, "Worse, those hooks might be spread throughout a system. Our research leads to a new way that can protect all the hooks in an efficient way, by moving them to a centralized place and thus making them easier to manage and harder to subvert."

Jiang explains that by placing all of the hooks in one place, researchers were able to simply leverage hardware-based memory protection, which is now commonplace, to prevent hooks from being hijacked. Essentially, they were able to put hardware in place to ensure that a rootkit cannot modify any hooks without approval from the user.

The research, "Countering Kernel Rootkits with Lightweight Hook Protection," will be presented at the 16th ACM Conference on Computer and Communications Security in Chicago, Nov. 12.

Source: North Carolina State University (news : web)


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4.9 /5 (13 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • mobiledemocracy - Nov 03, 2009
    • Rank: not rated yet
    I'm assuming that the operating system at the root of this article is Windows. Linux and GNU-related systems, along with applications designed for those systems need to become more developed and adopted into the mainstream.
  • jgelt - Nov 03, 2009
    • Rank: not rated yet
    There were rootkits before windows existed.
    There are rootkits for linux.
    Asking user permission 10,000 times is unmarketable and a pre approved list becomes a new target.
    It gets more complicated, not really more secure.
  • jgelt - Nov 03, 2009
    • Rank: 5 / 5 (1)
    Best personal security is a tamperproof OS (read only) on a removable device, with backup copies.
    No sharing computers, no leaving data on a computer, everything goes in your pocket and shy of mugging, your system is safe.
    At some date all memory storage devices may be undistinguishable by the OS. At that time, even windows becomes a portable OS de-facto.


November 3, 2009 all stories

Comments: 3

4.9 /5 (13 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Grisoft Offers Free Rootkit Removal
    created Apr 11, 2007 | popularity not rated yet | comments 0
  • Online poker targeted by cyber criminals
    created May 16, 2006 | popularity not rated yet | comments 0
  • Briefs: Microsoft to scrub out Sony piracy rootkit
    created Nov 15, 2005 | popularity not rated yet | comments 0
  • Free Anti-Rootkit Tools
    created Apr 24, 2007 | popularity not rated yet | comments 0
  • Anti-theft software could create security hole
    created Jul 31, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Will this game work on windows vista
    created 2 hours ago
  • Help with a camera choice
    created Nov 18, 2009
  • casio calculator that's similar to TI-89
    created Nov 08, 2009
  • Advice on what cell phone to get
    created Nov 08, 2009
  • More from Physics Forums - Computing & Technology

Other News

Hackers leak e-mails, stoke climate debate

Technology / Internet

created 1hour ago | popularity 5 / 5 (5) | comments 1

(AP) -- Computer hackers have broken into a server at a well-respected climate change research center in Britain and posted hundreds of private e-mails and documents online - stoking debate over whether some scientists have ...


plug-in hybrid electric vehicle

Pulling the plug on hybrid myths

Technology / Energy

created Nov 19, 2009 | popularity 3.8 / 5 (12) | comments 16

(PhysOrg.com) -- Whether you call them myths, urban legends, fables or old wives' tales, there's a lot of misinformation out there about plug-in electric hybrid vehicles. These vehicles, abbreviated PHEVs, ...


UK police make 2 Trojan computer virus arrests

Technology / Internet

created Nov 18, 2009 | popularity 5 / 5 (1) | comments 10

(AP) -- A couple suspected of helping spread some of the Internet's most aggressive computer viruses has been arrested in the English city of Manchester, police said Wednesday.


A sign marks the entrance to IBM Corporate Headquarters

IBM makes Big Blue cloud

Technology / Software

created Nov 16, 2009 | popularity 2.9 / 5 (8) | comments 8

IBM on Monday announced it has created the world's largest business computing "cloud" capable of holding an amount of digital data on a par with 250 billion iTunes songs.


Google SPDY

Google's SPDY will speed up downloads

Technology / Internet

created Nov 16, 2009 | popularity 4.4 / 5 (16) | comments 7

(PhysOrg.com) -- As part of its effort to speed up the Web, Google is experimenting with SPDY, a new application layer protocol, that it hopes will speed up the conversation between browsers and Web servers ...