首页> 外国专利> SYSTEM AND METHOD FOR DETECTING HIDDEN PROCESS USING SYSTEM EVENT INFORMATION

SYSTEM AND METHOD FOR DETECTING HIDDEN PROCESS USING SYSTEM EVENT INFORMATION

机译:利用系统事件信息检测隐藏过程的系统和方法

摘要

PROBLEM TO BE SOLVED: To provide a system and method for detecting a hidden process using system event information for detecting and controlling the hidden process.;SOLUTION: Since a hidden process which is executed using a code such as a rootkit also has the characteristic of using resources assigned from an OS of a system for executing the process, information for the hidden process is not shown in an application layer, but process relevant information is disclosed in a kernel layer in the process of using the system resources assigned. Therefore, in this system, a process list is extracted from the kernel layer using system event information which is provided in real-time access to the system resources, a process provided only to the kernel process is detected and controlled as the hidden process through comparison with a process list provided to a user from the application layer. Accordingly, the hidden process which is present in the system can be detected at real time.;COPYRIGHT: (C)2008,JPO&INPIT
机译:解决的问题:提供一种使用系统事件信息来检测隐藏过程的系统和方法,以检测和控制隐藏过程。解决方案:由于使用诸如rootkit之类的代码执行的隐藏过程还具有以下特征:使用从系统的OS分配的用于执行过程的资源,用于隐藏过程的信息未在应用程序层中显示,但是在使用分配的系统资源的过程中,在内核层中公开了与过程有关的信息。因此,在该系统中,使用实时访问系统资源提供的系统事件信息从内核层提取进程列表,通过比较将仅提供给内核进程的进程作为隐藏进程进行检测和控制。从应用程序层提供给用户的进程列表。因此,可以实时检测系统中存在的隐藏进程。版权所有:(C)2008,JPO&INPIT

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号