首页> 外国专利> Method and system for the detection of file system filter driver based rootkits

Method and system for the detection of file system filter driver based rootkits

机译:基于文件系统过滤器驱动程序的rootkit的检测方法和系统

摘要

A method, system, and computer program product for detecting hidden files and folders that may be installed by or as part of a rootkit provides the capability to identify the method that is used to hide the files and folders, will continue working even if the operating system is modified, and is suitable for real-time detection of hidden files and folders. A method for detecting a rootkit comprises the steps of generating a plurality of query input/output request packets, each query input/output request packet requesting information relating to a file system directory folder, transmitting a generated query input/output request packet to each file system driver object, receiving a result including the requested information relating to a file system directory folder from each file system driver object, and determining differences among each result, to determine information relating to a file system directory folder that is removed by at least one file system driver object.
机译:用于检测可能由rootkit安装或作为rootkit一部分安装的隐藏文件和文件夹的方法,系统和计算机程序产品提供了识别用于隐藏文件和文件夹的方法的功能,即使系统经过修改,适合实时检测隐藏的文件和文件夹。一种用于检测rootkit的方法,包括以下步骤:生成多个查询输入/输出请求包,每个查询输入/输出请求包请求与文件系统目录文件夹有关的信息;将生成的查询输入/输出请求包发送给每个文件。系统驱动程序对象,从每个文件系统驱动程序对象接收包括与文件系统目录文件夹有关的请求信息的结果,并确定每个结果之间的差异,以确定与被至少一个文件删除的文件系统目录文件夹有关的信息系统驱动程序对象。

著录项

  • 公开/公告号US7647308B2

    专利类型

  • 公开/公告日2010-01-12

    原文格式PDF

  • 申请/专利权人 AHMED SALLAM;

    申请/专利号US20060594096

  • 发明设计人 AHMED SALLAM;

    申请日2006-11-08

  • 分类号G06F17/30;

  • 国家 US

  • 入库时间 2022-08-21 18:49:58

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号