首页>
外国专利>
System and method for detecting hidden process using system event information
System and method for detecting hidden process using system event information
展开▼
机译:使用系统事件信息检测隐藏进程的系统和方法
展开▼
页面导航
摘要
著录项
相似文献
摘要
A system and method for detecting a hidden process using system event information are provided. The system includes: a kernel layer monitoring module for extracting system event information by monitoring a kernel layer system; a kernel layer process list detecting module for detecting processes related to an event from the extracted system event information; an application layer process list detecting module for detecting a process list provided to a user from an application layer; and a hidden process detecting module for detecting a process that is present only in the kernel layer as a hidden process by comparing the processes detected from the kernel layer process list detecting module and the processes detected from the application layer process list detecting module.
展开▼