
rootkit-detection-ebpf-time-trace
Detection of rootkit file hiding activities through analysis of shifts in kernel function execution times.
anomaly-detectioneducationintrusion-detection+2

Detection of rootkit file hiding activities through analysis of shifts in kernel function execution times.

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…