节点文献
Windows平台下Rootkit进程检测
Rootkit Process Detection under Windows Platform
【摘要】 Rootkit是能够持久或可靠地存在于计算机系统上的一组程序或代码。为了达到无法检测的目的,Rootkit必须使用进程隐藏技术。Rootkit进程隐藏技术是一种以秘密方式在系统后台运行并窃取用户信息的技术。通过分析Windows平台下Rootkit进程隐藏技术的原理,研究了应用层和内核层两种模式下的Rootkit进程隐藏技术。针对Rootkit进程隐藏技术的特点,开发了一个基于句柄表三位一体交叉映射的Rootkit隐藏进程检测平台。系统测试表明,本平台能够检测出当前绝大部分主流Rootkit技术实现的隐藏进程,在实际应用中达到了较好的效果。
【Abstract】 Rootkit is a set of procedures or code that is able to exist in a lasting or reliable computer system.In order not to detect the hidden process,Rootkit must use the technology of process hiding.The Rootkit process hiding is a kind of technology to run under system platform and steal user information as a secret way.By analyzing the principle of Rootkit process hiding under Windows platform,makes a comprehensive study about the technology of Rootkit process hiding.According to the characteristics of the Rootkit process hiding,develops a trinity and cross-mapping platform based on handle table for detecting the Rootkit hidden process.The experiment indicates that the platform can detect most of the current Rootkit hidden process and takes good effect in practice.
【Key words】 Rootkit; process hiding and detection; handle table; kernel object;
- 【文献出处】 计算机技术与发展 ,Computer Technology and Development , 编辑部邮箱 ,2011年07期
- 【分类号】TP316.7
- 【被引频次】5
- 【下载频次】127