O'Neill, Brian (2025) Linux Based Rootkit Detection Leveraging eBPF. Masters thesis, Dublin, National College of Ireland.
Preview |
PDF (Master of Science)
Download (893kB) | Preview |
Preview |
PDF (Configuration Manual)
Download (56kB) | Preview |
Abstract
Kernel rootkits inject code into kernel functions and can remain undetected due to their ability to hide their processes. Existing approaches fall short in the ability to provide adequate detection coverage and can be impractical in terms of the need to develop kernel modules or use extra hardware and can be inefficient use of resources in their detection. To address some of these challenges it is proposed that eBPF be leveraged for its ability to programming the kernel dynamically, and can be used for networking, observability, and security.
Previous work using eBPF for rootkit detection has approached the problem by observing the impact of rootkits on the performance of some system elements as an indicator of compromise. This has seen a degree of success. This work seeks to address the influence of system conditions on detection accuracy. It follows a methodology that creates and analysis timing data from targets gathered within the Linux kernel. By comparing clean data and data gathered in the presence of a rootkit it seeks to obverse difference in execution times of subsystem kernel functions due to the rootkit. Data is gathered dynamically to observe impacts of a rootkit on system events and at the same time gather kernel events that can help discriminate against events that will adversely affect accuracy in detection. Schedular policies are investigated as a mechanism to dampen down processes unrelated to the processes and task of the application at hand and produce cleaner data for analysis. Statistical significance was found in the impacts of rootkits on the chosen timing targets within the kernel and some marginal gains were found in masking off system noise.
| Item Type: | Thesis (Masters) |
|---|---|
| Supervisors: | Name Email Mustafa, Raza Ul UNSPECIFIED |
| Uncontrolled Keywords: | Rootkit detection; anomaly detection; eBPF; kernel probes; tracing |
| Subjects: | Q Science > QA Mathematics > Electronic computers. Computer science T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science Q Science > QA Mathematics > Computer software > Computer Security T Technology > T Technology (General) > Information Technology > Computer software > Computer Security |
| Divisions: | School of Computing > Master of Science in Cyber Security |
| Depositing User: | Ciara O'Brien |
| Date Deposited: | 18 Aug 2026 17:13 |
| Last Modified: | 18 Aug 2026 17:13 |
| URI: | https://norma.ncirl.ie/id/eprint/9547 |
Actions (login required)
![]() |
View Item |
Tools
Tools