首页>
外国专利>
Method and apparatus for detecting hidden network communication channels of rootkit tools
Method and apparatus for detecting hidden network communication channels of rootkit tools
展开▼
机译:Rootkit工具的隐藏网络通信通道的检测方法和装置
展开▼
页面导航
摘要
著录项
相似文献
摘要
Methods and apparatuses for detecting hidden network channels of rootkit tools are described. In one embodiment, critical endpoint events detected at an endpoint computer system are selectively logged to an endpoint database. Also, critical network events associated with the endpoint computer system and detected on a network are selectively logged to a gateway database. Periodically some or all of the entries in the endpoint database are compared to entries in the gateway database. Entries detected at the network but not detected at the endpoint computer system are presumed indicative of hidden network channels of rootkit tools.
展开▼