节点文献

基于系统调用挂钩的隐蔽木马程序检测方法

Stealthy Trojan Horse Detection Method Based on System Call Hook

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 梁晓李毅超崔甲曹跃

【Author】 LIANG Xiao,LI Yi-chao,CUI Jia,CAO Yue(Laboratory of Network Attack & Defense,School of Computer Science and Engineering,University of Electronic Science and Technology of China,Chengdu 610054)

【机构】 电子科技大学计算机科学与工程学院网络攻防实验室电子科技大学计算机科学与工程学院网络攻防实验室 成都610054成都610054

【摘要】 隐蔽木马程序的设计本质是劫持常规的执行路径流,当前大多数检测手段无法全面检测出隐蔽性日益增强的木马程序。该文结合操作系统程序执行流程的局部相关性与确定性,在分析用户进程空间与内核空间中系统函数调用标志信息的基础上,检测系统中是否存在木马程序设置的隐蔽性系统调用挂钩,设计并实现了相应的检测方法。与现有的检测方法相比,该方案弥补了检测未知木马的不足,检测结果更全面。

【Abstract】 Trojan horses design essence lies in hijacking execution routine,and most of current detection methods fail to completely identify such ever-increasingly covert Trojan horses.The paper presents an approach to detect the existence of system call hooks set by Trojan horses based on the locality and determinacy of execution flows,and the analysis of system function call labs in both user and kernel levels,then designs and realizes corresponding prototype.Compared with current detections,the method offsets the deficiency in identifying unknown Trojan horses with more complete detection results.

【关键词】 特洛伊木马RootKit系统调用挂钩入侵检测
【Key words】 Trojan horseRootkitsystem callhookintrusion detection
【基金】 国家科技基础条件平台工作基金资助项目(2003DIA7J051)
  • 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2007年20期
  • 【分类号】TP309.5
  • 【被引频次】26
  • 【下载频次】397
节点文献中: 

本文链接的文献网络图示:

本文的引文网络