跳到主要导航 跳到搜索 跳到主要内容

Hidden process detection method based on intercepting the entry of system kernel

  • Sen Lin Luo
  • , Guang Lu Yan
  • , Li Min Pan*
  • , Fan Feng
  • , Hao Chen Liu
  • *此作品的通讯作者
  • Beijing Institute of Technology

科研成果: 期刊稿件文章同行评审

摘要

At present, hidden process detection methods are avoidable, poor compatibility or high wastage. A method based on intercepting the entry of system kernel was proposed to solve these problems. The method applies the process behavior of communicating with system kernel to intercept the three channels: KiFastCallEntry, IDT and GDT, which were from user layer to kernel layer. Furthermore, the method applied the semantic reconstruction to establish the process list of kernel layer, and then combined with cross-view to detect hidden processes. The experiments show that the method proposed in this paper can detect all kinds of hidden processes at present. The method can be used in the majority of Windows operating system and it has higher detection accuracy, better compatibility, lower wastage and stronger pragmatic value.

源语言英语
页(从-至)545-550
页数6
期刊Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology
35
5
DOI
出版状态已出版 - 1 5月 2015

指纹

探究 'Hidden process detection method based on intercepting the entry of system kernel' 的科研主题。它们共同构成独一无二的指纹。

引用此