首页> 外国专利> System and method for detecting hidden process using system event information

System and method for detecting hidden process using system event information

机译:使用系统事件信息检测隐藏进程的系统和方法

摘要

A system and method for detecting a hidden process using system event information are provided. The system includes: a kernel layer monitoring module for extracting system event information by monitoring a kernel layer system; a kernel layer process list detecting module for detecting processes related to an event from the extracted system event information; an application layer process list detecting module for detecting a process list provided to a user from an application layer; and a hidden process detecting module for detecting a process that is present only in the kernel layer as a hidden process by comparing the processes detected from the kernel layer process list detecting module and the processes detected from the application layer process list detecting module.
机译:提供了一种使用系统事件信息来检测隐藏进程的系统和方法。该系统包括:内核层监视模块,用于通过监视内核层系统来提取系统事件信息;以及内核层进程列表检测模块,用于从提取的系统事件信息中检测与事件相关的进程;应用层进程列表检测模块,用于检测从应用层提供给用户的进程列表;隐藏进程检测模块,用于通过比较从内核层进程列表检测模块检测到的进程和从应用层进程列表检测模块检测到的进程,将仅存在于内核层中的进程检测为隐藏进程。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号