NORMA eResearch @NCI Library

Linux Based Rootkit Detection Leveraging eBPF

O'Neill, Brian (2025) Linux Based Rootkit Detection Leveraging eBPF. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (893kB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (56kB) | Preview

Abstract

Kernel rootkits inject code into kernel functions and can remain undetected due to their ability to hide their processes. Existing approaches fall short in the ability to provide adequate detection coverage and can be impractical in terms of the need to develop kernel modules or use extra hardware and can be inefficient use of resources in their detection. To address some of these challenges it is proposed that eBPF be leveraged for its ability to programming the kernel dynamically, and can be used for networking, observability, and security.

Previous work using eBPF for rootkit detection has approached the problem by observing the impact of rootkits on the performance of some system elements as an indicator of compromise. This has seen a degree of success. This work seeks to address the influence of system conditions on detection accuracy. It follows a methodology that creates and analysis timing data from targets gathered within the Linux kernel. By comparing clean data and data gathered in the presence of a rootkit it seeks to obverse difference in execution times of subsystem kernel functions due to the rootkit. Data is gathered dynamically to observe impacts of a rootkit on system events and at the same time gather kernel events that can help discriminate against events that will adversely affect accuracy in detection. Schedular policies are investigated as a mechanism to dampen down processes unrelated to the processes and task of the application at hand and produce cleaner data for analysis. Statistical significance was found in the impacts of rootkits on the chosen timing targets within the kernel and some marginal gains were found in masking off system noise.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Mustafa, Raza Ul
UNSPECIFIED
Uncontrolled Keywords: Rootkit detection; anomaly detection; eBPF; kernel probes; tracing
Subjects: Q Science > QA Mathematics > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 18 Aug 2026 17:13
Last Modified: 18 Aug 2026 17:13
URI: https://norma.ncirl.ie/id/eprint/9547

Actions (login required)

View Item View Item