GOVCERT.NL Symposium 2008. 16 & 17 September - World Trade Center Rotterdam
How Sustainable is Your Security?
Pär Österberg Medina Incident Handler SITIC - Swedish IT-Incident Centre

Pär Österberg-Medina (CISSP) started his career in Unix and Windows network administration, but quickly migrated into solely security-related work, such as the administration of firewall and intrusion-detection systems. After carrying out penetration testing for various consulting firms for several years, he started to work for the Swedish Gvt CERT (Sitic), where, for the past five years, amongst other things, he has been handling IT incidents.

Finding Rootkits in Memory Dumps Wednesday 17 September, 13:40 - 14:25, Leeuwen Room

With the increasing threat of computer intrusions that avoid writing data to the hard drive and the rise of malware utilizing rootkit technology, we need to include memory analysis in our incident investigation process. This presentation will focus on the different methods and techniques that can be used by an organization in order to find machines on which rootkits have been installed.

First of all, we will start by explaining how a rootkit stays undetected in the system, which tricks it can use and how it can survive a reboot. The next step is to dump the memory of the system that we suspect has been compromised. Different types of memory dumping techniques will be demonstrated, plus how anti-forensics can be used in order to fool the rootkits.

Finally, the presentation will cover how the memory image can be analyzed and how the infection is revealed. There will be live demonstrations of various tools and techniques, how these can be used to find rootkit infections, and help us to find out whether or not a machine has been compromised.

Please respect your privacy and review our privacy statement. GOVCERT.NL does not guarantee the correctness or completeness of third party information sources mentioned on this website, even if linked to directly. Except where noted, content on this site is licensed under a Attribution-Share Alike 3.0 Netherlands License.