Presentation is loading. Please wait.

Presentation is loading. Please wait.

RootKit By Parrag Mehta OUTLINE What is a RootKit ? Installation Types How do RootKits work ? Detection Removal Prevention Conclusion References.

Similar presentations


Presentation on theme: "RootKit By Parrag Mehta OUTLINE What is a RootKit ? Installation Types How do RootKits work ? Detection Removal Prevention Conclusion References."— Presentation transcript:

1

2 RootKit By Parrag Mehta

3 OUTLINE What is a RootKit ? Installation Types How do RootKits work ? Detection Removal Prevention Conclusion References

4 What is a RootKit ? Software that allows continued privilege access to a computer system without the system users knowledge. RootKit comes from “Root” – UNIX administrator account and “Kit” – Software components that implement the tool.

5 INSTALLATION Exploit Security Vulnerabilities Cracking a Password Trick user into executing malicious code Social Engineering – Malware is beneficial

6 TYPES Persistent – Activated every time system starts up Non-persistent – Not capable of running again on system start up Way in which they execute – User Mode – Kernel Mode

7 How do RootKits work ? RootKits use a simple concept called “Modification” Some places where modifications can be made in the software: – Patching – Easter Eggs – Spyware Modifications – Source-Code Modifications – Legality of Software Modifications

8 DETECTION Alternative trusted medium Behavioral-based Signature-based Difference-based Integrity-based Memory Dump

9 REMOVAL Re-install OS from trusted media – Highly recommended – Re-install from scratch Anti-virus software – Malicious software removal tool – AVG Pro – SpySweeper

10 PREVENTION Use Anti-virus Software Install a Firewall Use good passwords Keep Software up to date Follow good security practices

11 CONCLUSION Thus, we have seen what Rootkits are, how they work, how can they be detected and removed and also what are the prevention mechanisms. We also conclude that there is no concrete method to detect and remove RootKits.

12 REFERENCES http://en.wikipedia.org/wiki/Rootkit#cite_not e-48 http://en.wikipedia.org/wiki/Rootkit#cite_not e-48 http://www.bestsecuritytips.com/xfsection+ar ticle.articleid+122+page+1.htm http://www.bestsecuritytips.com/xfsection+ar ticle.articleid+122+page+1.htm http://www.informit.com/articles/article.aspx ?p=408884&seqNum=5 http://www.informit.com/articles/article.aspx ?p=408884&seqNum=5

13 THANK YOU


Download ppt "RootKit By Parrag Mehta OUTLINE What is a RootKit ? Installation Types How do RootKits work ? Detection Removal Prevention Conclusion References."

Similar presentations


Ads by Google