2.5 Basic Operating Principles of Rootkit Technologies
165
2.5 Basic Operating Principles of Rootkit Technologies
2.5.1 What Is a Rootkit Technology?
Let us consider the main types of technologies applied by malware developers, which
cannot be considered viruses due to the lack of ability to reproduce: they include
rootkits, keyloggers, Trojans, and spyware [1].
The term “rootkit” historically originates from the Unix world, where it is used to
refer to the set of utilities installed by the hacker on a computer after gaining primary
access. They include standard hacking tools (sniffers, scanners) and Trojan utilities
substituting basic Unix utilities. The rootkit technology allows the hacker to settle
in the hacked system and cover traces of their activity.
In Windows, rootkits are usually programs that intrude the system and intercept
system functions or replace system libraries. Interception and modification of lowlevel API functions first of all allows such program to sufficiently hide its presence
in the system, protecting it from being detected by the user and antivirus software.
Moreover, many rootkits can mask the presence of any processes, folders, files, and
register keys described in their configuration in the system. Many rootkits install
their own drivers and services in the system (they are invisible as well).
Developers of viruses, Trojans, and spyware lately have been actively embedding
rootkit technologies in their malware, e.g., Trojan-Spy. Win32.Qukart, which masks
its presence in the system using rootkit technology (it should be noted that its rootkit
mechanism works perfectly in Windows 95\98\ME\2000\XP).
In order to combat rootkits effectively, it is necessary to understand the principles
and mechanisms of their operation. All rootkit technologies can be conventionally
subdivided into two categories: user mode rootkits and kernel mode rootkits. The first
category of rootkits is based on intercepting functions of libraries of the user level
and the second one on installing a system driver intercepting kernel level functions.
Below is a more detailed examination of the main methods of interception of functions
applicable to rootkits, even though the described methods are universal and applied
by many useful programs and utilities.
2.5.2 Methods of Intercepting API Functions in User Mode
We will use descriptions of function interception methods [1, 16] with simplified
schemes of their work; red dotted arrow shows interruption of a rootkit into the work
of the program, while red solid arrows indicate deviations in the work logic caused
by rootkit interference.
Interception of functions allows rootkits to modify the results of their work
significantly. For instance, interception of a function of file search on a disk helps
exclude masked files from search results, while interception of functions of the type
ZwQuerySystemlnformation helps mask the running processes and loaded libraries.
165
2.5 Basic Operating Principles of Rootkit Technologies
2.5.1 What Is a Rootkit Technology?
Let us consider the main types of technologies applied by malware developers, which
cannot be considered viruses due to the lack of ability to reproduce: they include
rootkits, keyloggers, Trojans, and spyware [1].
The term “rootkit” historically originates from the Unix world, where it is used to
refer to the set of utilities installed by the hacker on a computer after gaining primary
access. They include standard hacking tools (sniffers, scanners) and Trojan utilities
substituting basic Unix utilities. The rootkit technology allows the hacker to settle
in the hacked system and cover traces of their activity.
In Windows, rootkits are usually programs that intrude the system and intercept
system functions or replace system libraries. Interception and modification of lowlevel API functions first of all allows such program to sufficiently hide its presence
in the system, protecting it from being detected by the user and antivirus software.
Moreover, many rootkits can mask the presence of any processes, folders, files, and
register keys described in their configuration in the system. Many rootkits install
their own drivers and services in the system (they are invisible as well).
Developers of viruses, Trojans, and spyware lately have been actively embedding
rootkit technologies in their malware, e.g., Trojan-Spy. Win32.Qukart, which masks
its presence in the system using rootkit technology (it should be noted that its rootkit
mechanism works perfectly in Windows 95\98\ME\2000\XP).
In order to combat rootkits effectively, it is necessary to understand the principles
and mechanisms of their operation. All rootkit technologies can be conventionally
subdivided into two categories: user mode rootkits and kernel mode rootkits. The first
category of rootkits is based on intercepting functions of libraries of the user level
and the second one on installing a system driver intercepting kernel level functions.
Below is a more detailed examination of the main methods of interception of functions
applicable to rootkits, even though the described methods are universal and applied
by many useful programs and utilities.
2.5.2 Methods of Intercepting API Functions in User Mode
We will use descriptions of function interception methods [1, 16] with simplified
schemes of their work; red dotted arrow shows interruption of a rootkit into the work
of the program, while red solid arrows indicate deviations in the work logic caused
by rootkit interference.
Interception of functions allows rootkits to modify the results of their work
significantly. For instance, interception of a function of file search on a disk helps
exclude masked files from search results, while interception of functions of the type
ZwQuerySystemlnformation helps mask the running processes and loaded libraries.
