跳到主要导航 跳到搜索 跳到主要内容

高可靠In-VM隐藏进程对抗检查方法

  • Beijing Institute of Technology

科研成果: 期刊稿件文章同行评审

摘要

Executing malicious code via hidden process is a major way to carry out information attack. At present, hidden process detection methods based on In-VM model of virtualization platform can be attacked by circumventing and tampering with the relative data. To solve this problem, a highly reliable In-VM hidden process detection method was proposed. Firstly, an In-VM model and the memory protection mechanism of virtualization were developed to protect its detection code and relative kernel data from being maliciously changed. Secondly,by hijacking the system transfer function exactly and detecting the hidden process with a cross-view method, the detection algorithm was ensured from being circumvented. Finally, several typical Rootkits were built and chosen in experiments. The results show that, the proposed method can detect all kinds of hidden processes. Its detection code and relative kernel data cannot be tampered with and its detection algorithm and memory protection mechanism cannot be circumvented. And the developed memory protection mechanism has better performance in the system, showing a higher reliability and stronger pragmatic value.

投稿的翻译标题A Highly Reliable In-VM Hidden Process Detection Countermeasure
源语言繁体中文
页(从-至)305-312
页数8
期刊Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology
38
3
DOI
出版状态已出版 - 1 3月 2018

关键词

  • Hidden process
  • In-VM model
  • Process detection
  • Rootkit
  • Virtualization

指纹

探究 '高可靠In-VM隐藏进程对抗检查方法' 的科研主题。它们共同构成独一无二的指纹。

引用此