摘要
Executing malicious code via hidden process is a major way to carry out information attack. At present, hidden process detection methods based on In-VM model of virtualization platform can be attacked by circumventing and tampering with the relative data. To solve this problem, a highly reliable In-VM hidden process detection method was proposed. Firstly, an In-VM model and the memory protection mechanism of virtualization were developed to protect its detection code and relative kernel data from being maliciously changed. Secondly,by hijacking the system transfer function exactly and detecting the hidden process with a cross-view method, the detection algorithm was ensured from being circumvented. Finally, several typical Rootkits were built and chosen in experiments. The results show that, the proposed method can detect all kinds of hidden processes. Its detection code and relative kernel data cannot be tampered with and its detection algorithm and memory protection mechanism cannot be circumvented. And the developed memory protection mechanism has better performance in the system, showing a higher reliability and stronger pragmatic value.
| 投稿的翻译标题 | A Highly Reliable In-VM Hidden Process Detection Countermeasure |
|---|---|
| 源语言 | 繁体中文 |
| 页(从-至) | 305-312 |
| 页数 | 8 |
| 期刊 | Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology |
| 卷 | 38 |
| 期 | 3 |
| DOI | |
| 出版状态 | 已出版 - 1 3月 2018 |
关键词
- Hidden process
- In-VM model
- Process detection
- Rootkit
- Virtualization
指纹
探究 '高可靠In-VM隐藏进程对抗检查方法' 的科研主题。它们共同构成独一无二的指纹。引用此
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver