Lastline Aims to Stay Ahead of Windows Kernel Malware

Published: Mar 20, 2015
Updated: Feb 2, 2021
2 minute read
malware
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Malware exists in many forms and is used to attack many different technologies, including Microsoft’s Windows operating system kernel. Security firm Lastline announced a new capability to detect kernel malware, complemented by a presentation March 17 at the South by Southwest (SXSW) conference on the state of malware.

“There is malware today that injects itself directly into the kernel, and the problem is that it enables the malware to run with high privileges,” Engin Kirda, Lastline co-founder and chief architect, told eWEEK.

Since the kernel malware runs with high privileges, most modern security software and sandboxing techniques fail to detect the malware, making it more difficult to stop it from doing harm, Kirda said.

Kernel malware isn’t the same as rootkit malware although the two can be related, he said, adding that a rootkit is a group of malware tools designed to give an attacker control of a vulnerable system.

“A rootkit doesn’t necessarily have to run in the kernel, so an attacker could write code that runs in user space,” Kirda said. “A rootkit could also potentially run in the kernel.”

Much of the Windows kernel space is read-only in order to prevent unauthorized loading of code, and a user-level program typically cannot write code that will execute in the kernel, he explained.

“Attackers will often use vulnerabilities in the kernel to overwrite the write protection,” Kirda said.

Most modern antivirus software leverages heuristics technologies in order to help identify potential malware, yet in Kirda’s analysis, that’s not enough to find kernel-level malware.

The new Lastline capability to gain visibility into kernel malware is derived from how Lastline performs emulation. Lastline’s Breach Detection Platform leverages the open-source QEMU (Quick EMUlator) with additional modifications and extensions in order to perform full system emulation. Lastline partners and integrates its technology with multiple vendors, including Dell SecureWorks, Blue Coat, Tripwire, Juniper and Barracuda.

Advertisement

With the new Lastline 6.5 release, there is additional visibility and capabilities to see if something is actually being loaded into the kernel, Kirda said.

“Since we’re able to see every single instruction that is executed in the kernel, we can look for malicious behaviors that are indicative of malware,” Kirda said. “So if something ends up in the kernel and does something you would not normally expect to see, we can flag that.”

While Kirda has seen an increase in kernel malware, for the most part, he hasn’t seen it be widely used in automated exploitation tools and kits. Most of the kernel malware attacks that Kirda has seen have been very targeted and were not automated. Now that Lastline has the new deep level of visibility, the company will continue to research new ways of improving the technology to stay one step ahead of attackers, Kirda said.

“We expect that kernel malware will become even more evasive,” Kirda said.

Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

Sean Michael Kerner

Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。