ArticleslgStudy

computer science

The Rootkit Arsenal

The Rootkit Arsenal is a computer science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand The Rootkit Arsenal rather than just read about it. In short: The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System is a book written by Bill Blunden, published by Jones & Bartlett Publishers in May 2009. The book takes the reader in depth about rootkit technology and uses.

The Rootkit Arsenal — main illustration
The Rootkit Arsenal — illustration

Key takeaways

  • The Rootkit Arsenal belongs to computer science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect The Rootkit Arsenal to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of The Rootkit Arsenal from memory before moving on to harder problems.

Reference excerpt

The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System is a book written by Bill Blunden, published by Jones & Bartlett Publishers in May 2009. The book takes the reader in depth about rootkit technology and uses. It covers topics such as IA-32 assembly, the Windows system architecture, kernel debugging, advanced rootkit development, and much more concerning rootkit technology and how it can be applied onto e.g. white hat hacking. The book also provides many source code examples on rootkit development and how to properly use it. It is required and recommended to have a fair understanding of computer programming and operating systems in order to fully comprehend the contents of the book, as the back cover states it is an advanced book on its topic.

Content The book is divided into four parts, and each of the 14 chapters goes into detail about specific technology and information required in advanced rootkit development and use. It also provides information about network and file system analyses, kernel objects, drivers, and much more related to rootkit technology. The reader can create a fully working rootkit by using the source codes in the appendix. The product description states that the book sheds light on material that has traditionally been poorly documented, partially documented, or intentionally undocumented.

Reviews The book has received mostly positive reviews from websites specializing in computer reviews. Computing Reviews writes about this book "This book addresses a controversial and timely issue in the field of network security. Rootkits are notoriously used by the black hat hacking community. A rootkit allows an attacker to subvert a compromised system. This subversion can take place at the application level, as is the case for the early rootkits that replaced a set of common administrative tools, but can be more dangerous when it occurs at the kernel level. A rootkit hides the network traffic, processes, and files that an attacker decides to keep invisible to administrators and system management tools… If you work on defensive solutions—anti-virus and malware detection tools—or are interested in low-level system programming, you must read this book. In fact, for the intended audience, this is one of the best books of 2009." Richard Austin of the IEEE's Computer Society's Technical Committee on Security and Privacy also published a review of the book's second edition in 2014.

Notes

References Blunden, Bill. The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System. 1st ed. Jones & Bartlett Publishers, 2009 Blunden, Bill. The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System. 2st ed. Jones & Bartlett Publishers, 2012

Worked examples

Example 1 — a first encounter with The Rootkit Arsenal

Start with the simplest possible case. Write down what The Rootkit Arsenal claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In computer science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to The Rootkit Arsenal before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about The Rootkit Arsenal ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of The Rootkit Arsenal

In research
The Rootkit Arsenal appears in computer science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses The Rootkit Arsenal in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
The Rootkit Arsenal is common in secondary-school and first-year university syllabi. It links to neighbouring topics 2009 non-fiction books, Computer science books, Rootkits, so understanding it makes those chapters shorter.
In everyday life
Look for The Rootkit Arsenal outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.
Ask Teacher Smith questions about this articleOpens your AI tutor with a question about “The Rootkit Arsenal” →

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study The Rootkit Arsenal in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what The Rootkit Arsenal means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain The Rootkit Arsenal out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is The Rootkit Arsenal in simple terms?

The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System is a book written by Bill Blunden, published by Jones & Bartlett Publishers in May 2009. The book takes the reader in depth about rootkit technology and uses.

Why does The Rootkit Arsenal matter?

Because it connects several computer science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study The Rootkit Arsenal?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on The Rootkit Arsenal.

Tags

  • 2009 non-fiction books
  • Computer science books
  • Rootkits

Keep exploring