• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2007, Vol. 29 ›› Issue (7): 1-3.

• 论文 •    下一篇

一种基于交叉视图的Windows Rootkit检测方法

陈晓苏 黄文超 肖道举   

  • 出版日期:2007-07-01 发布日期:2010-06-02

  • Online:2007-07-01 Published:2010-06-02

摘要:

针对互联网上日益流行的Windows Rootkit程序的实现机制,本文分析了现有的检测方法,指出了其中可能存在的不足,在此基础上提出了一种基于交叉视图的Windows Rootk it检测方法,给出了基本检测思想以及具体实现步骤,讨论了其中关键检测步骤的处理过程,并通过一个有代表性的实例给出了实际的检测效果。

关键词: Rootkit 隐藏 系统服务描述表 挂钩

Abstract:

The paper analyses different techniques of the Rootkit detection, which integrates the implementation of Windows rootkits that are widely spreaded on   the Internet, and points out their limitation. On this basis, a method based on cross-view is proposed to detect malicious programs, subsequently the ma   in idea and implementation steps are presented. Experimental results demonstrate the efficiency of our method.

Key words: Rootkit, hide, SSDT, hook