首页> 外文会议>2012 Fourth International Conference on Multimedia Information Networking and Security. >Towards a Novel Approach for Hidden Process Detection Based on Physical Memory Scanning
【24h】

Towards a Novel Approach for Hidden Process Detection Based on Physical Memory Scanning

机译:寻求一种基于物理内存扫描的隐藏过程检测的新方法

获取原文
获取原文并翻译 | 示例

摘要

Leveraging developed root kit, malware could deeply hide its own process and hardly be detected. Based on analyzing various existing detecting technologies, a novel approach for hidden process detection was proposed in this paper. The approach used page table entry patching to traverse physical memory and obtain the raw data, and formulated the characteristic selection constraints to extract reliable process object characteristics, which were used to search process object instances based on string matching in physical memory to form a credible list of processes. The approach could also be used to search other kernel objects on varieties of system platforms. The experimental results show that new detection is effective in hidden process searching.
机译:利用已开发的根工具包,恶意软件可以深深地隐藏其自身的进程,几乎无法被发现。在分析各种现有检测技术的基础上,提出了一种新的隐藏过程检测方法。该方法使用页表项修补来遍历物理内存并获取原始数据,并制定了特征选择约束条件以提取可靠的过程对象特征,这些特征用于根据物理存储器中的字符串匹配来搜索过程对象实例以形成可信列表。的过程。该方法还可以用于在各种系统平台上搜索其他内核对象。实验结果表明,新的检测方法在隐藏过程搜索中是有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号