Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2010, Vol. 36 ›› Issue (11): 120-122. doi: 10.3969/j.issn.1000-3428.2010.11.043

• Networks and Communications • Previous Articles     Next Articles

Method of Key-logger Based on SSDT and Callback Function

CHEN Jun-jie1, SHI Yong2, XUE Zhi2, CHEN Xin1   

  1. (1. College of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai 200240; 2. College of Information Security Engineering, Shanghai Jiaotong University, Shanghai 200240)
  • Online:2010-06-05 Published:2010-06-05

基于SSDT及回调函数的键盘记录方法

陈俊杰1,施 勇2,薛 质2,陈 欣1   

  1. (1. 上海交通大学电子信息与电气工程学院,上海 200240;2. 上海交通大学信息安全工程学院,上海 200240)
  • 作者简介:陈俊杰(1984-),男,硕士研究生,主研方向:驱动开发,信息安全;施 勇,博士研究生;薛 质,教授、博士生导师; 陈 欣,硕士研究生

Abstract: The technology of anti-key loggers update quickly, and the existent key-logger method has various defects. Aiming at this situation, this paper presents a new type of key-logger. Based on Shadow System Service Description Table(SSDT) and callback function of kernel layer, this method combines the user mode and the kernel mode. It makes the whole design to break the current record of the mainstream anti-keyboard instruments. It has high stability, versatility, and strong stealthiness.

Key words: key-logger, callback function, Shadow System Service Description Table(SSDT), active defense

摘要: 当前反键盘记录技术更新迅速,且传统键盘记录方法存在较多缺陷。针对该现状,提出一种新型的键盘记录方法。该方法基于Shadow系统服务描述表(SSDT)及底层回调函数,关联用户模式和内核模式,可以突破目前主流的反键盘记录手段,同时稳定性高、通用性好、隐蔽性强。

关键词: 键盘记录, 回调函数, Shadow系统服务描述表, 主动防御

CLC Number: