LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > Programming
User Name
Password
Programming This forum is for all programming questions.
The question does not have to be directly related to Linux and any language is fair game.

Notices


Reply
  Search this Thread
Old 04-08-2008, 11:52 PM   #1
return.c
LQ Newbie
 
Registered: Mar 2008
Distribution: Fedora
Posts: 11

Rep: Reputation: 0
Sys call hooking - tracing


I am developing a small program to monitor the Linux kernel for any Trojan / rootkit infection. I want to monitor the kernel, if any malware changes the system calls and alert the user. How to do this or what function calls to use for monitoring system call hooking ?
 
Old 04-09-2008, 06:42 PM   #2
jailbait
LQ Guru
 
Registered: Feb 2003
Location: Virginia, USA
Distribution: Debian 12
Posts: 8,340

Rep: Reputation: 550Reputation: 550Reputation: 550Reputation: 550Reputation: 550Reputation: 550
You might be able to do what you want by using the kernel debug routine:

http://www.ibm.com/developerworks/li...brary/l-kdbug/

-----------------
Steve Stites
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
System call tracing for IDS .... how???? lonelyfloyd Linux - Software 3 04-05-2008 12:05 PM
tracing 'create' system call called by any process to kernel viv_nan Linux - General 3 03-07-2007 11:09 AM
question about select sys call xatzipol Programming 1 10-30-2005 09:22 AM
tracing the error code returned by wait call lg3 Linux - Software 0 02-21-2005 03:53 AM
Kill sys call eshwar_ind Programming 4 05-07-2004 11:41 AM

LinuxQuestions.org > Forums > Non-*NIX Forums > Programming

All times are GMT -5. The time now is 05:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration