期刊文献+

基于远程线程注入的进程隐藏技术研究 被引量:12

Research on remote-thread injection based hidden process technology
下载PDF
导出
摘要 Windows系统平台下的进程隐藏方法中远程线程注入技术比较常见,但常规的远程线程注入技术难以避过安全检测技术的检测。针对于此,提出了基于APC机制的远程线程注入技术,通过利用APC机制实现新的攻击策略,以达到进程隐藏的目的。并在分析技术原理基础上,针对该技术改进了安全检测方案。在实际检测中该攻击方法隐蔽性更强,能有效对抗常规的安全检测技术。 The remote-thread injection technology is one normal method of hidden process in Windows, but it's hard to confront security detection technology. A new remote-thread injection technology was proposed based on APC mechanism. It made use of APC mechanism to realize a new attack strategy of hiding process. Finally the detection technology based on the principle of APC mechanism was improved. In fact this attack method is more concealed, so it can confront normal hidden process detection techniques.
出处 《计算机应用》 CSCD 北大核心 2008年第B06期92-94,共3页 journal of Computer Applications
关键词 ROOTKIT 进程隐藏 远程线程注入 APC机制 RootKit hidden process remote-thread injection APC mechanism
  • 相关文献

参考文献9

  • 1BUTELER J R I L. Detecting compromises of core subsystems and kernel function in Windows NT/2000/XP: M. S. Thesis[ D]. Baltimore County: University of Maryland, 2002.
  • 2DOROTHY E. Denning, information warfare and security[ M]. Boston: Addison Wesley, 2001.
  • 3雷校勇,黄小平.Windows RootKit技术原理及防御策略[D].上海:上海交通大学,2006.
  • 4齐琪.Windows下EPA技术的研究与改进[D].武汉:华中科技大学,2006.
  • 5BUTLER J, JEFFREY L, PINKSON J. Hidden processes: The implication for intrusion detection[ C]//Proceedings of the 2003 IEEE Workshop on Assurance United States Military Academy. West Point: IEEE Press, 2003.
  • 6王建华,张焕生,侯丽坤.Windows核心编程[M].北京:机械工业出版社,2001.
  • 7LEVINE J G, GRIZZARD J B, HUTTO P W, et al. A methodology to characterize kernel level rootkit exploits that overwrite the system call table[ C]// Proceeding of IEEE SoutheastCon. Washington: IEEE Press, 2004:25 - 31.
  • 8GREG H, JAMES B. RootKit: Subverting the Windows kernel[ M]. Boston: Addison Wesley, 2005.
  • 9SCHREIBER S B. Undocumented Windows 2000 secrets: A programmer's cookbook [ M]. Boston: Addison Wesley, 2001.

共引文献3

同被引文献81

引证文献12

二级引证文献40

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部