The papers and articles at this site are quite interesting, even if a little dated. Somehow I had many of them opened from a couple of days ago but just now took the time to really read them.
Guidelines for C source code auditing: http://www.ouah.org/mixtercguide.html
Syscall Proxying – Simulating remote execution: http://www.ouah.org/SyscallProxying.pdf
An Overview of Unix Rootkits: http://www.ouah.org/iRootkits.pdf