摘要
木马技术是网络安全的重要方面,也是网络攻击中获取信息的重要途径。隐藏技术是木马的关键技术之一,其直接决定木马的生存能力。从Rootkit的原理分析出发,深入的研究Windows下内核级木马的隐藏技术,并在此基础上实现一个内核级木马原型,最后介绍内核级木马的检测和应对策略。
Trojan horse technology is an important part in the research of network security, and it's also an important way to get information from the network. This paper mainly analyzes the concealment and detecting technology of windows Rootkit - based trojan horse. A kernel - level Trojan horse system is implemented as well. Finally, some ways to detect Trojan horse are described in detail.
出处
《微处理机》
2009年第1期41-44,48,共5页
Microprocessors