节点文献
基于线程调度的进程隐藏检测技术研究
Research on Thread Dispatch Based Hidden Process Detection Technique
【摘要】 基于线程调度的进程隐藏检测技术,利用操作系统进程的资源分配和调度机理,通过直接扫描系统内核中的活动线程来逆向检测实际存在的进程列表信息。该方法可以检测出当前常规安全检测工具不能发现的系统恶意程序的入侵行为。和现有的进程隐藏检测方法相比,该检测方式克服了各种缺陷,具有更加彻底可靠的安全机制,可以检测出当前所有类型的进程隐藏。
【Abstract】 Thread dispatch based hidden processes detection technique makes use of the process’s resource assignment and dispatch mechanism in operating system to scan active threads in system kernel for reverse detecting active processes list. This method can detect more Trojan horse’s intrusions than general security detection software. Comparing with normal hidden process detection techniques, it has gotten over all of the limitations, and found all types of current hidden processes based on more reliable secure mechanism.
【关键词】 特洛伊木马;
Rootkit;
进程隐藏;
线程调度;
入侵检测;
【Key words】 Trojan horse; Rootkit; Process hiding; Thread dispatch; Intrusion detection;
【Key words】 Trojan horse; Rootkit; Process hiding; Thread dispatch; Intrusion detection;
- 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2006年10期
- 【分类号】TP393.08
- 【被引频次】23
- 【下载频次】403