Research on Rootkit Detection Method Based on Neural Network Expert System in Virtualized Environment

ZHAO Zhi-yuan, ZHU Zhi-qiang, SUN Lei and MA Ke-xin   

Abstract: In order to solve the problems about the high misjudgment ratio of Rootkit detection and undetectable unknown Rootkit in the virtualization guest operating system,a Rootkit detection method(QPSO_BP_ES) based on neural network expert system was proposed.The detection system combines neural network with expert system,which can take advantage of them.In the actual detection,QPSO_BP_ES firstly captures the previously selected Rootkit’s typical characteristic behaviors.And then,the trained system detects the presence of Rootkit.The experimental results show that QPSO_BP_ES can effectively reduce the misjudgment ratio and detect both known and unknown Rootkit.

Key words: Virtualization,QPSO,Neural network,Expert system,Rootkit

