节点文献

一种自动检测内核级Rootkit并恢复系统的方法

A Method to Automatically Detect and Recover from Kernel Level Rootkit

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 颜仁仲钟锡昌张倪

【Author】 YAN Renzhong1,2, ZHONG Xichang3, ZHANG Ni3 (1. Institute of Computing Technology, Chinese Academy of Sciences, Beijing 100080; 2. Graduate School of Chinese Academy of Sciences, Beijing 100039; 3. Software Center, Chinese Academy of Sciences, Beijing 100080)

【机构】 中国科学院计算技术研究所中国科学院研究生院 北京100039中国科学院软件中心北京100080

【摘要】 Rootkit是黑客入侵系统后保留后门常用的一项技术。目前不存在一种能自动检测内核级rookit并恢复系统的方法。该文在详细剖析内核级rootkit原理的基础上,提出了一种自动检测内核级rootkit并恢复系统的方法。该方法不仅对目前出现的所有内核级rootkit有效,而且考虑了将来可能出现的更高级的rootkit。

【Abstract】 Rootkit is a common technology used by hackers to keep backdoors on the compromised system. There is no method to automatically detect and recover from kernel level rootkits at present. This paper analyzes the principle of kernel level rootkits, and proposes a method to automatically detect and recover from kernel level rootkits. This method is useful to the existing rootkits and the rootkits that may appear in future.

  • 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2006年10期
  • 【分类号】TP309.3
  • 【被引频次】19
  • 【下载频次】247
节点文献中: 

本文链接的文献网络图示:

本文的引文网络