摘要
分析现有的两类Rootkit检测方法。根据内核级Rootkit在系统中的隐藏机制,提出了一种基于文件系统异常的有效检测方法。实验表明,该方法能够简便快捷地检测出内核级Rootkit的存在,帮助系统管理员进一步维护系统安全。
This paper analyzed the existed methodologies to detect Rootkit. According to the hiding mechanism of kernel-level Rootkit in the operating system, proposed an effective detecting method based on filesystem anomalies. The experiment indicates that it can detect the existence of kernel-level Rootkit in a simple process and help system administrators further maintain security.
出处
《计算机应用研究》
CSCD
北大核心
2009年第8期3056-3057,3062,共3页
Application Research of Computers