Evaluate Namespace as a Labeling System for Malware Detection
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
Nowadays, kernel tracing tools are built on limited Linux features. In this thesis, we explore a new method to help improving kernel tracing. We modified Memorizer, a novel kernel tracing tool that offers a comprehensive coverage of kernel accesses, and combined it with the Linux Namespace system. As an original compartment feature in Linux, introducing namespaces gives us a chance to describe kernel accesses and exploit behaviors in a different perspective. Experiments showed that our modified Memorizer can provide novel insights about how the kernel works between modules and containers. Moreover, we proposed a series of analysis methods that allows us to extract a small and unique profile for a certain exploit, which could contribute to developing security identifying software in the future.
Description
Advisor
Degree
Type
Keywords
Citation
Ding, Chenkai. "Evaluate Namespace as a Labeling System for Malware Detection." (2021) Master’s Thesis, Rice University. https://hdl.handle.net/1911/111748.