2015
DOI: 10.1007/978-3-319-20550-2_2
|View full text |Cite
|
Sign up to set email alerts
|

“Nice Boots!” - A Large-Scale Analysis of Bootkits and New Ways to Stop Them

Abstract: Bootkits are among the most advanced and persistent technologies used in modern malware. For a deeper insight into their behavior, we conducted the first large-scale analysis of bootkit technology, covering 2,424 bootkit samples on Windows 7 and XP over the past 8 years. From the analysis, we derive a core set of fundamental properties that hold for all bootkits on these systems and result in abnormalities during the system's boot process. Based on those abnormalities we developed heuristics allowing us to det… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1

Citation Types

0
4
0

Year Published

2017
2017
2020
2020

Publication Types

Select...
3
2
1

Relationship

0
6

Authors

Journals

citations
Cited by 6 publications
(4 citation statements)
references
References 15 publications
0
4
0
Order By: Relevance
“…This is before the moment the OS can use its antimalware protection [7], so research is desired also in the field of detecting bootkits. Bernhard Grill and the collective of authors of [7] introduce Bootcamp -a framework capable, as they say in [7] of detecting and analysing bootkits. The architecture of their solution utilizes a group of Bootcamp Workers [7] that run virtual machines.…”
Section: Introductionmentioning
confidence: 99%
See 2 more Smart Citations
“…This is before the moment the OS can use its antimalware protection [7], so research is desired also in the field of detecting bootkits. Bernhard Grill and the collective of authors of [7] introduce Bootcamp -a framework capable, as they say in [7] of detecting and analysing bootkits. The architecture of their solution utilizes a group of Bootcamp Workers [7] that run virtual machines.…”
Section: Introductionmentioning
confidence: 99%
“…Bernhard Grill and the collective of authors of [7] introduce Bootcamp -a framework capable, as they say in [7] of detecting and analysing bootkits. The architecture of their solution utilizes a group of Bootcamp Workers [7] that run virtual machines. The sample of bootkits are analysed within these VMs [7].…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…This chapter covers RQ3 and RQ4, with a method and environment to study the storagerelated behavior of bootkit malware, techniques to stop bootkit attacks, and possible evolution paths for bootkit technologies. Chapter 3 appeared in the Proceedings of the 12th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA '15) [62].…”
Section: Organization Of the Dissertationmentioning
confidence: 99%