Numchecker - A System Approach for Kernel Rootkit Detection

Numchecker - A System Approach for Kernel Rootkit Detection

Black Hat via YouTube Direct link

Detection: Performance Evaluation

12 of 16

12 of 16

Detection: Performance Evaluation

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Numchecker - A System Approach for Kernel Rootkit Detection

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 Executive Summary
  3. 3 Kernel Rootkit Behavior Classification
  4. 4 Hardware Performance Counters (HPC)
  5. 5 Two-Phase Detection and identification
  6. 6 Syscall Measurement
  7. 7 Kernel Preemption Handling
  8. 8 Detection: Test Programs
  9. 9 Detection: Choosing Proper Events
  10. 10 Detection: Deviation Threshold
  11. 11 Detection: Kernel Rootkits Detected
  12. 12 Detection: Performance Evaluation
  13. 13 Identification: Kernel Rootkits Identified
  14. 14 Identification: Periodic Sampling
  15. 15 Security Analysis
  16. 16 Conclusion

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.