期刊文献+

一种新型系统安全检测软件的设计与实现 被引量:1

Design and Implementation of a New System Security Detection Software
下载PDF
导出
摘要 基于SDK平台,采用内核检测技术,设计开发了一种监视注册表值的变化;检测病毒、木马等恶意软件隐藏的文件、进程及内核模块等主要功能的新型的系统安全检测软件。通过进程端口映射查找系统打开的端口信息有效地查找木马及NTFS流文件中的流病毒;通过查看BHO、LSP防止浏览器和网络被劫持;通过查看HOOK的SSDT及SSDT Shadow恢复被修改的内容。经实际系统测试与比较表明,系统能有效地保障系统软件的安全。 Based on the SDK platform, by adopting kernel inspection technology, this paper designs and develops a new system security detection software for monitoring changes of registry value and detecting files, processes ahd kernel modules hidden by malicious software like virus and cockhorse. Port messages opened by the system are found by means of process port mapping for effective search of stream virus in cockhorse and NTFS stream files. BHO and I_SP are examined to prevent hijacking of browsers and networks. HOOK's SSDT and SSDT Shadow are checked to recover modified items. Actual system tests and comparison indicate that this system can effectively guarantee the safety of the system software.
作者 张永刚
出处 《电气自动化》 2015年第5期27-29,88,共4页 Electrical Automation
基金 国家自然科学基金(60971297) 定西师范高等专科学校校级项目基金(13JJ9022)资助
关键词 SDK平台 安全检测 设计 实现 系统服务描述表 输入输出请求包 根权限工具 SDK platform security detection design implementation system service descriptor table (SSDT) I/O request packet ( IRP ) rootkit
  • 相关文献

参考文献4

二级参考文献22

  • 1王斌君,景乾元等.信息安全体系[M].北京:高等教育出版社,2008.
  • 2Michael J Ktchabaw,Hanan L Lutfiyya,Andrew D.Marshall Policy-Driven Fault Management in Distributed Systems Software ReliabilityEngineering [C]//Proceedings-Dept.of Comput.Sci.,Univ.ofWestern Ontario,London,Ont,1996.
  • 3Ferenc Bodon Informatics Laboratory,Computer and Automation Re-search Institute Hungarian Academy of Sciences H-llll Budapest,h'agymr anyosi u.11,Hungary.
  • 4司徒放,曹建.基于事件的分布式系统监控[D].上海交通大学,2010.
  • 5Matteo Migliavacca,Ioannis Papagiannis,David M Eyers,et al.Dis-tributed Middleware Enforcement of Event Flow Security Policy[C]//Lecture Notes in Computer Science,2010,6452:334-354.
  • 6Gerald G Koch,Boris Koldehofe,Kurt Rothermel.Cordies:expressiveevent correlateion in distributed systems [C] //DEBS 10 Proceedingsof the Fourth ACM International Conference on Distributed Event-Based Systems ACM New York,NY,USA,2010.
  • 7吉根林,孙志挥.分布式数据库关联规则挖掘与更新研究[D].东南大学,2011.
  • 8Akdere M,Cetintemel U,Tatbul N.plan-based Complex Event Detec-tion Across Distributed Sources [C]//Proceedings of the VLDB En-dowment.August 2008:66-77.
  • 9Pietzuch P R,Shand B,Bacon J.Composite event detection as a genericmiddleware extension[J].Network,IEEE,2004,18(1):44-45.
  • 10TURING A M. Computing machinery and intelligence [ J ]. Mind, 1950,236( 1 ) :433-460.

共引文献22

同被引文献17

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部