检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]河海大学计算机及信息工程学院,江苏南京210098
出 处:《计算机技术与发展》2010年第3期207-210,共4页Computer Technology and Development
基 金:国家高技术(863)计划项目(2007AA01Z179)
摘 要:监控系统要求具有实时性和隐藏性,远程线程注入技术能实现在Windows系统下进程的隐藏。将监控程序编译成动态链接库(DLL)文件,采用远程线程注入技术注入到系统进程运行,能有效地提高监控系统的安全性能。本文介绍了远程线程注入技术的原理,分析了基于远程线程注入的监控系统的关键技术和实现方法,通过设置定时器的方法解决了系统实时性需求,通过给出的远程线程注入技术解决了隐藏性需求。最后分析采用两级监控和应对安全检测技术来提高监控系统的安全性。The monitor system demands a characteristic of real time and hiding. The process can be hidden by remote - thread injection technique in Windows system. The monitor program is compiled to DLL and injected into system process to run. In this way, the safety of monitor system can be enhanced effectively. The theory of remote - thread injection technique is presented in this paper. The main technique and implementation method of monitor system based on remote- thread injection technique is analyzed, by setting timer to solve the demands of system' s real time, through the remote - thread injection technique to solve the demands of hiding. At last, the two- stage monitor technique and the responding to safety detection technique are discussed to improving the safety of monitor system.
分 类 号:TP277[自动化与计算机技术—检测技术与自动化装置]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.33