Domain Ontology to Distinguish Different Types of Rootkits

  ahmad salahi
  Javad Enayatizadeh
Keywords: Ontology, Rootkit, Malware, Security


Rootkit is an auxiliary tool for sniffing, stealing and hiding, so it has become the key component in almost all successful attacks. Analysis of rootkits will provide system administrators and security software managers the ability to detect and prevent a computer being compromised. Ontology will provide detailed conceptualization to represent the rootkit concepts and its relationships to other security concepts in cyber-attack domain. In this paper we presented an ontology for rootkits which contains many concepts relating to security, cyber-attacks and operating systems. We divided rootkits according to four attributes, and expanded the ontology for rootkits accordingly. This ontology can be used to distinguish different types of rootkits.


ahmad salahi

Ahmad Salahi  received M.SC. from Tehran university in 1970, M.S. from Kansas University, Lawrence Kansas in 1974, and Ph.D. from Purdue uiversity, West Lafayette,Indiana,U.S.A. in 1979 all in electrical engineering. He is currently an associate professor in Iranian Research Institute for ICT (ex. ITRC). His research interests are network security, switching and routing.

Javad Enayatizadeh

Javad Enayatizadeh received Master degree in Information Technology from Iran university of science & technology in 2010. His main interest is in programming software that focuses on network.


