检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
出 处:《计算机应用》2011年第9期2362-2366,共5页journal of Computer Applications
基 金:国家863计划项目(2008AA10Z419);河南省基础与前沿技术研究计划项目(082300410150)
摘 要:利用进程对象特征搜索内存能够检测到隐藏进程。但是,借助不断发展的Rootkit,恶意程序可以修改内存地址映射关系绕过虚拟内存扫描,或篡改进程信息使检测特征失效,从而增加了搜索检测的难度。针对此问题,提出一种基于多特征匹配的隐藏进程检测方法:利用页表项循环补丁技术直接扫描物理内存,得到完整可信的内存信息;选取多个进程数据结构字段构建检测特征模板,提高特征自身的可靠性;引入相似度进行匹配防止单特征失效而导致的漏检。实验结果表明,该方法对隐藏进程具有较好的检测效果。Based on certain detection characteristics of process, hidden process could be uncovered by memory searching. However, malware, with the help of developing Rootkit, could hardly be detected because its feature has been manipulated or virtual memory scan could be invalid, thus increasing the difficulty of detection. In order to address this issue, a new multi-characteristics matching approach was proposed. It was to obtain the whole physical memory image by Page Table Entry (PTE) patching, to extract the key fields from process data structure and construct a template to improve the reliability of characteristics, and to introduce similarity for preventing the detection leakage. The results show that the new detection is effective in the hidden process searching.
分 类 号:TP309.5[自动化与计算机技术—计算机系统结构] TP316.7[自动化与计算机技术—计算机科学与技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.15