Lord Of The Ring 0 - Cybersecurity Conference

Lord Of The Ring 0

Abstract: As the Linux kernel evolves with enhanced security features, increases deprecation of various symbols (e.g. system call table) and features (e.g. disabling memory protection); and security monitoring evolves with deeper visibility into the internals, traditional rookit methods do not work on modern systems. To remain invisible, modern offensive tooling must move beyond simple hooking and embrace more sophisticated stealth mechanisms. This talk explores kernel-mode stealth mechanisms for modern Linux kernels enabling us to hide our traces from user-mode.

Talk outline: The following topics will be discussed in the following tentative order:

1. Introduction to kernel hooking

  1.1 Hooking kernel functions (kprobe, kretprobe, ftrace)

  1.2 Hooking filesystem (fanotify, stackable filesystem, mount binds, FUSE, kernel mode filesystem)

  1.3 Introduction to VFS

2. Hiding files and directories

  2.1 Preventing file I/O

  2.2 Hiding using FUSE

  2.3 Hiding using stackable filesystem

  2.4 Hiding using kernel mode filesystem

  2.5 Hiding using VFS hooking

3. Hiding processes

  3.1 Hiding process based on name

  3.2 Hiding process based on PID

  3.3 Hiding process by hooking kill

4. Hiding network activity

  4.1 Hiding open ports

  4.2 Hiding connection to IP

5. Detection and mitigation techniques

Adhokshaj Mishra – Linux agent

Adhokshaj Mishra works as Staff Detection Engineer – Linux agent, specializing in Linux, container and Kubernetes platforms. His interest lies in the offensive and defensive side of Linux malware research. He has been working on container specific attacks, and detections in his professional career. In his free time, he mostly researches about new offensive techniques in malware as well as applied cryptography. He loves speaking in security meetups and conferences; and has presented in various local security chapter meetups, apart from other security events.

Animesh Roy

Animesh Roy is an offensive security practitioner with 13+ years across application security, red team operations, and penetration testing. He runs Arishti Security, researches and discloses vulnerabilities, and builds tooling that makes security testing sharper.