期刊文献+

基于指令跳转分析的Windows RootKit动态检测技术 被引量:1

Dynamic Rootkit Detection Methodology Based on Branch Instruction Analysis
下载PDF
导出
摘要 RootKit是用来维持黑客对计算机控制,使之无法检测的强力工具。当前传统的RootKit技术都有相对应的检测技术。文章介绍了内核对象内联挂接技术,延伸了现有的代码重定向技术,通过对内核对象调用路径的内联挂接,实现隐藏。现有的RootKit检测技术很难检测这种新型RootKit。因此,文章提出了基于指令跳转分析的动态RootKit检测技术,可以动态检测内核对象内联挂接的RootKit,并且能够指出这些RootKit程序的加载映像。 RootKit is a set of powerful tools used by hackers to gain the access to the computers and make itself undetectable. This paper introduces a technique named kernel object inline hooking, which extends existing technique of code redirection, hides tracks through inline hooking of kernel object~ dispatch routines. Existing detecting methodology of rootkit is difficult to detect this kind of new rootkit, So this paper illustrates a branch instruction analysis based dynamic detecting methodol- ogy of rootkit. This methodology could find running rootkit programs dynamically in the system, and point out the loading images of these rootkits.
出处 《信息工程大学学报》 2007年第2期221-226,共6页 Journal of Information Engineering University
基金 国家自然科学基金资助项目(60473021)
关键词 ROOTKIT 内联挂接 跳转分析 rootkit inline hooking branch instruction analysis
  • 相关文献

参考文献21

  • 1Greg H, James B. Rootkits: Subverting the Windows Kernel [ M ]. Addison-Wesley Professional,2005.
  • 2Ntoskrnl. Windows File Protection: How To Disable It On The Fly[EB/OL].(2005 - 10 - 10 ). http://www. egocrew, de/board/archive/3838/thread, html.
  • 3Fuzen. FU Rootkit[EB/OL].(2005 - 09 - 15). http ://www. rootkit, com/project, php? id = 12.
  • 4Hunt G, D Brubacher. Detours: Binary Interception of [ Win321 Functions [ C ]//Proceedings of the 3rd USENIX Windows NT Symposium. Seattle, WA, July 1999: 135 - 143.
  • 5HolyFather. Hacker Defender Rootkit[EB/OL].(2005 -05 - 18 ). http ://www. rootkit, host. sk/.
  • 6Greg H. NT Rootkit[EB/OL]. (2005 - 12 - 19). http ://www. rootkit, tom/project, php? id=11.
  • 7Hoglund. Kernel Object Hooking Rootkits (KOH Rootkits)[EB/OL]. ( 2005 - 06 - 02 ). http ://www. rootkit. com/newsread, php? newsid = 501.
  • 8Joanna R. Thoughts about Cross-View based Rootkit Detection [ EB/OL ]. ( 2005 - 08 - 15 ). http ://invisiblethings. org.
  • 9Bryce Cogswell, Mark Russinovich. Rootkit Revealer[EB/OL].( 2005 - 08 - 15 ). http ://www. sysinternals. corn/Files/RootkitRevealer, zip.
  • 10Joanna R. Concepts for the Stealth Windows Rootkit[EB/OL].( 2004 - 10 - 08 ). http ://invisiblethings. org/.

同被引文献6

引证文献1

二级引证文献6

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部