节点文献

基于线程调度的进程隐藏检测技术研究

Research on Thread Dispatch Based Hidden Process Detection Technique

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 梁晓李毅超

【Author】 LIANG Xiao LI Yi-Chao (College of Computer Science and Engineering, UEST of China, Chengdu 610054)

【机构】 电子科技大学计算机科学与工程学院电子科技大学计算机科学与工程学院 成都610054成都610054

【摘要】 基于线程调度的进程隐藏检测技术,利用操作系统进程的资源分配和调度机理,通过直接扫描系统内核中的活动线程来逆向检测实际存在的进程列表信息。该方法可以检测出当前常规安全检测工具不能发现的系统恶意程序的入侵行为。和现有的进程隐藏检测方法相比,该检测方式克服了各种缺陷,具有更加彻底可靠的安全机制,可以检测出当前所有类型的进程隐藏。

【Abstract】 Thread dispatch based hidden processes detection technique makes use of the process’s resource assignment and dispatch mechanism in operating system to scan active threads in system kernel for reverse detecting active processes list. This method can detect more Trojan horse’s intrusions than general security detection software. Comparing with normal hidden process detection techniques, it has gotten over all of the limitations, and found all types of current hidden processes based on more reliable secure mechanism.

  • 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2006年10期
  • 【分类号】TP393.08
  • 【被引频次】23
  • 【下载频次】403
节点文献中: