...
【24h】

A New Method for Protecting User Mode from Root Kit Malwares

机译:从Rootkit恶意软件保护用户模式的新方法

获取原文
           

摘要

The dominant operating system in the world today is windows. There are some of the weaknesses present in the window architecture. Using this weakness root kit malware wants to utilize an administrative control of the windows, root kit malwares refers to software that is used to conceal the presence and permit an attacker to take control of a system. So, an attacker can capture the sensitive information that present in a system. To reduce the number of root kit injection first, we classify the legitimate and suspicious code using an algorithm if the process is a legitimate one means that the legitimate process is directly permitted to get the system service through the ntdll.dll which acts as a gateway to the kernel mode from the user mode. If it is a suspicious code means, it will be processed through the customized ntdll.dll. Monitor program is used to customize the ntdll.dll by hook.dll, using which the prevalidation and validation function is added in the ntdll.dll. Pre-validation is done by generating password for a suspicious code using a scrambling technique, then by using we unscramble the dispatch-ID which was scrambled in the user mode and redirect the control to the validation function if it matches with any of the system services, otherwise the control will be disallowed. It provides an additional protection that avoids the system crash and allows only the legitimate program to accomplish the system services.
机译:当今世界上最主要的操作系统是Windows。窗口体系结构中存在一些弱点。使用这种弱点,root kit恶意软件希望利用对Windows的管理控制,root kit恶意软件是指用于隐藏存在并允许攻击者控制系统的软件。因此,攻击者可以捕获系统中存在的敏感信息。为了首先减少根工具包的注入次数,如果进程是合法的,则我们使用一种算法对合法和可疑的代码进行分类,这意味着可以直接允许合法进程通过充当网关的ntdll.dll获取系统服务。从用户模式转到内核模式。如果是可疑的代码手段,它将通过自定义的ntdll.dll进行处理。监视程序用于通过hook.dll自定义ntdll.dll,使用该程序可以在ntdll.dll中添加预验证和验证功能。通过使用加扰技术为可疑代码生成密码来进行预验证,然后使用我们对在用户模式下加扰的dispatch-ID进行解密,然后将其重定向到验证功能(如果它与任何系统服务匹配)。 ,否则该控件将被禁止。它提供了额外的保护,避免了系统崩溃,并且仅允许合法程序完成系统服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号