Cloaker: Hardware supported rootkit concealment

Francis M. David, Ellick M. Chan, Jeffrey C. Carlyle, Roy H. Campbell

Research output: Chapter in Book/Report/Conference proceedingConference contribution


Rootkits are used by malicious attackers who desire to run software on a compromised machine without being detected. They have become stealthier over the years as a consequence of the ongoing struggle between attackers and system defenders. In order to explore the next step in rootkit evolution and to build strong defenses, we look at this issue from the point of view of an attacker. We construct Cloaker, a proof-of-concept rootkit for the ARM platform that is non-persistent and only relies on hardware state modifications for concealment and operation. A primary goal in the design of Cloaker is to not alter any part of the host operating system (OS) code or data, thereby achieving immunity to all existing rootkit detection techniques which perform integrity, behavior and signature checks of the host OS. Cloaker also demonstrates that a self-contained execution environment for malicious code can be provided without relying on the host OS for any services. Integrity checks of hardware state in each of the machine's devices are required in order to detect rootkits such as Cloaker. We present a framework for the Linux kernel that incorporates integrity checks of hardware state performed by device drivers in order to counter the threat posed by rootkits such as Cloaker.

Original languageEnglish (US)
Title of host publicationProceedings - 2008 IEEE Symposium on Security and Privacy, SP
Number of pages15
StatePublished - 2008
Event2008 IEEE Symposium on Security and Privacy, SP - Oakland, CA, United States
Duration: May 18 2008May 21 2008

Publication series

NameProceedings - IEEE Symposium on Security and Privacy
ISSN (Print)1081-6011


Other2008 IEEE Symposium on Security and Privacy, SP
Country/TerritoryUnited States
CityOakland, CA

ASJC Scopus subject areas

  • General Engineering


Dive into the research topics of 'Cloaker: Hardware supported rootkit concealment'. Together they form a unique fingerprint.

Cite this