首页> 外国专利> Method and system for detecting windows rootkit that modifies the kernel mode system service dispatch table

Method and system for detecting windows rootkit that modifies the kernel mode system service dispatch table

机译:用于检测Windows rootkit修改内核模式系统服务分发表的方法和系统

摘要

A method, system, and computer program product for detecting a kernel-mode rootkit that hooks the System Service Dispatch Table (SSDT) is secure, avoids false positives, and does not disable security applications. A method for detecting a rootkit comprises the steps of calling a function that accesses a system service directly, receiving results from calling the function that accesses the system service directly, calling a function that accesses the system service indirectly, receiving results from calling the function that accesses the system service indirectly, and comparing the received results from calling the function that accesses the system service directly and the received results from calling the function that accesses the system service indirectly to determine presence of a rootkit.
机译:用于检测挂接到系统服务调度表(SSDT)的内核模式rootkit的方法,系统和计算机程序产品是安全的,避免了误报,并且不禁用安全应用程序。一种用于检测rootkit的方法,包括以下步骤:调用直接访问系统服务的功能,从调用直接访问系统服务的功能接收结果,调用间接访问系统服务的功能,从调用该功能的结果接收结果。间接访问系统服务,并比较调用直接访问系统服务的函数收到的结果和调用间接访问系统服务的函数收到的结果,以确定rootkit的存在。

著录项

  • 公开/公告号US2008127344A1

    专利类型

  • 公开/公告日2008-05-29

    原文格式PDF

  • 申请/专利权人 AHMED SALLAM;

    申请/专利号US20060594095

  • 发明设计人 AHMED SALLAM;

    申请日2006-11-08

  • 分类号G06F21/00;

  • 国家 US

  • 入库时间 2022-08-21 20:13:41

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号