摘要
At present, hidden process detection methods are avoidable, poor compatibility or high wastage. A method based on intercepting the entry of system kernel was proposed to solve these problems. The method applies the process behavior of communicating with system kernel to intercept the three channels: KiFastCallEntry, IDT and GDT, which were from user layer to kernel layer. Furthermore, the method applied the semantic reconstruction to establish the process list of kernel layer, and then combined with cross-view to detect hidden processes. The experiments show that the method proposed in this paper can detect all kinds of hidden processes at present. The method can be used in the majority of Windows operating system and it has higher detection accuracy, better compatibility, lower wastage and stronger pragmatic value.
| 源语言 | 英语 |
|---|---|
| 页(从-至) | 545-550 |
| 页数 | 6 |
| 期刊 | Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology |
| 卷 | 35 |
| 期 | 5 |
| DOI | |
| 出版状态 | 已出版 - 1 5月 2015 |
指纹
探究 'Hidden process detection method based on intercepting the entry of system kernel' 的科研主题。它们共同构成独一无二的指纹。引用此
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver