节点文献

Windows平台下Rootkit进程检测

Rootkit Process Detection under Windows Platform

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张登银陈召国

【Author】 ZHANG Deng-yin,CHEN Zhao-guo(College of Computer,Nanjing University of Posts & Telecommunications,Nanjing 210003,China)

【机构】 南京邮电大学计算机学院

【摘要】 Rootkit是能够持久或可靠地存在于计算机系统上的一组程序或代码。为了达到无法检测的目的,Rootkit必须使用进程隐藏技术。Rootkit进程隐藏技术是一种以秘密方式在系统后台运行并窃取用户信息的技术。通过分析Windows平台下Rootkit进程隐藏技术的原理,研究了应用层和内核层两种模式下的Rootkit进程隐藏技术。针对Rootkit进程隐藏技术的特点,开发了一个基于句柄表三位一体交叉映射的Rootkit隐藏进程检测平台。系统测试表明,本平台能够检测出当前绝大部分主流Rootkit技术实现的隐藏进程,在实际应用中达到了较好的效果。

【Abstract】 Rootkit is a set of procedures or code that is able to exist in a lasting or reliable computer system.In order not to detect the hidden process,Rootkit must use the technology of process hiding.The Rootkit process hiding is a kind of technology to run under system platform and steal user information as a secret way.By analyzing the principle of Rootkit process hiding under Windows platform,makes a comprehensive study about the technology of Rootkit process hiding.According to the characteristics of the Rootkit process hiding,develops a trinity and cross-mapping platform based on handle table for detecting the Rootkit hidden process.The experiment indicates that the platform can detect most of the current Rootkit hidden process and takes good effect in practice.

【基金】 国家自然科学基金项目(61071093);国家863计划项目(2009AA701202);Swedish Research Links Programme(348-2008-6212);留学回国人员项目(NJ209002)
  • 【文献出处】 计算机技术与发展 ,Computer Technology and Development , 编辑部邮箱 ,2011年07期
  • 【分类号】TP316.7
  • 【被引频次】5
  • 【下载频次】127
节点文献中: 

本文链接的文献网络图示:

本文的引文网络