Talk With an Expert

Rootkit Detection with OSSEC

Rootkit Detection with OSSEC (PDF, 5.13MB)Published: 16 Apr, 2014
Created by
Sally Vandeven

Rootkits are one the most insidious forms of malware because they are designed to hide their existence on a system making them very difficult to detect. Yet there are utilities that claim to be effective at rootkit detection. OSSEC is one such utility. It is an open source host based IDS/IPS that also includes rootkit detection for Linux systems. This paper will examine and measure OSSEC's ability to detect and identify several different Linux rootkits including both user mode and kernel mode variants.