预览加载中,请您耐心等待几秒...
1/2
2/2

在线预览结束,喜欢就下载吧,查找使用更方便

如果您无法下载资料,请参考说明:

1、部分资料下载需要金币,请确保您的账户上有足够的金币

2、已购买过的文档,再次下载不重复扣费

3、资料包下载后请先用软件解压,在使用对应软件打开

Windows下基于交叉视图的Rootkit进程隐藏检测技术 Abstract Rootkitisatypeofmalicioussoftwarethatcanconcealitsownprocessesandactivityfromtheoperatingsysteminordertoremainunnoticedandtherefore,undetected.Oneofthechallengesindetectingrootkitisidentifyingitsprocessesinthesystem.Inthispaper,wefocusonthecross-viewbasedtechniquefordetectingrootkit’shiddenprocessesandactivitiesonWindowsoperatingsystem. Introduction Rootkitisatypeofmalwarethatisintendedtostayhiddenfromtheuserandevadedetectionbytheoperatingsystem.Itworksbyhidingitsprocesses,files,networkconnections,andregistrykeys,thusmakingitdifficulttodetectbytheoperatingsystem.Thismakesitapreferredtoolforattackerstousewhentheywanttoexploitasystemandstealdataorcontrolitremotely. Rootkitsaredividedintotwocategories:user-modeandkernel-mode.Kernel-moderootkitsresideinthekernelandhavehigherprivilegesthanuser-moderootkits,whichresideinuserspace.Duetotheirprivilegedposition,kernel-moderootkitsaremoredifficulttodetectandremovethanuser-moderootkits. Oneofthetechniquesemployedbyrootkitstoevadedetectionisprocesshiding.Therootkithidesitsprocessfromtheoperatingsystembymanipulatingthesystemcalltable,rootkithooks,orcreatinghiddenfilesandprocesses.Inthispaper,we’lllookathowcross-viewbasedtechniquecanhelpindetectinghiddenprocessesinWindows. Cross-viewbaseddetectiontechnique TherearetwoviewmethodsinWindowssystemfordetectingprocesses.Theyarethekernelviewanduserview.Thekernelviewprovidesanoverviewofthekernelprocesses,whiletheuserviewprovidesanoverviewoftheuserprocesses.Rootkitcansuccessfullyevadedetectionineitheroftheseviews,sometimesinboth. Therefore,todetectarootkitprocess,itisnecessarytousebothviews.Thisisknownascross-viewbaseddetectiontechnique.Inthistechnique,thekernelanduserviewsarecombinedtoprovideamorecomprehensiveoverviewofthesystemprocesses.Thisisachievedbycomparingtheprocesslistsobtainedfrombothviewsandidentifyingthedifferencesbetweenthem. Ifthereisadifferenceintheprocesslistbetweenthekernelanduserviews,thenthereisahighpossibilitythatarootkitprocessi