首页> 外国专利> ROOTKIT MEASUREMENT METHOD, APPARATUS, AND SERVER

ROOTKIT MEASUREMENT METHOD, APPARATUS, AND SERVER

机译:rootkit测量方法,装置和服务器

摘要

Disclosed by the embodiments of the present invention are a rootkit measurement method, apparatus, and server; said method can be applied to a Linux system; said Linux system comprises a secure backup area which is backed up with a system call table; the Linux system is divided into a ring3 state and a ring0 state. The method comprises: if it is detected that a Linux system is running, then loading a kernel module pre-deployed in the Linux system, and triggering an obtain program in the kernel module to obtain a current system call table in the ring0 state; obtaining the system call table, which has been backed up beforehand, from the secure backup area, and calling a comparison program in the ring3 state to determine whether the backed-up system call table is consistent with the current system call table; if not, then determining that the ring0 state of the Linux system has been attacked by the rootkit. The embodiments of the present invention are advantageous to improving the accuracy of rootkit detection.
机译:本发明实施例公开了一种rootkit的测量方法,装置和服务器;所述方法可以应用于Linux系统。所述Linux系统包括安全备份区域,该安全备份区域由系统调用表备份; Linux系统分为ring3状态和ring0状态。该方法包括:如果检测到Linux系统正在运行,则加载该Linux系统中预先部署的内核模块,并在该内核模块中触发获取程序,以获取ring0状态的当前系统调用表。从安全备份区域中获取预先备份的系统调用表,并以ring3状态调用比较程序,以确定备份的系统调用表是否与当前系统调用表一致;如果不是,则确定Linux系统的ring0状态已被rootkit攻击。本发明实施例有利于提高Rootkit检测的准确性。

著录项

  • 公开/公告号WO2020000741A1

    专利类型

  • 公开/公告日2020-01-02

    原文格式PDF

  • 申请/专利权人 PING AN TECHNOLOGY (SHENZHEN) CO. LTD.;

    申请/专利号WO2018CN108469

  • 发明设计人 ZHENG BIAO;

    申请日2018-09-28

  • 分类号G06F21/56;

  • 国家 WO

  • 入库时间 2022-08-21 11:14:06

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号