作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (10): 118-120. doi: 10.3969/j.issn.1000-3428.2009.10.039

• 安全技术 • 上一篇    下一篇

Windows Rootkit隐藏技术与综合检测方法

左黎明,蒋兆峰,汤鹏志   

  1. (华东交通大学基础科学学院,南昌 330013)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-05-20 发布日期:2009-05-20

Concealing Technology of Windows Rootkit and Integrated Detection Method

ZUO Li-ming, JIANG Zhao-feng, TANG Peng-zhi   

  1. (School of Basic Science, East China Jiaotong University, Nanchang 330013)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-05-20 Published:2009-05-20

摘要: 针对Rootkit具有隐藏、通信、监听等功能但存在典型木马特征对计算机系统危害严重问题,分析近年来Windows操作系统下Rootkit中各种主流隐藏技术(包括DKOM和各种钩子),指出当前单一检测方法的缺陷,提出综合性检测技术方案。实验结果表明,该方法达到较好的检测效果,可以对目前大多数Rootkit行为进行检测。

关键词: Rootkit技术, 系统服务描述符表, 隐藏

Abstract: Rootkit is a program or a set of programs that an intruder uses to hide her presence on a computer system and to allow access to the computer system. This paper analyses the main concealing techniques of Windows Rootkits, including DKOM and Hook, inner Windows system and points out the limitation of these single detection method. An integrated detection method is proposed to detect Rootkits. The main idea and implementation steps are presented. Experimental result shows that it owns satisfied detection effect, and can detect most actions of Rootkit.

Key words: Rootkit technology, System Service Descriptor Table(SSDT), concealing

中图分类号: