journal6 ›› 2009, Vol. 30 ›› Issue (4): 48-51.
• 计算机 • 上一篇 下一篇
出版日期:
发布日期:
作者简介:
Online:
Published:
摘要:研究了基于Windows操作系统分层驱动技术的内核rootkit,阐述了rootkit如何加入分层驱动程序链,并从IRP中获取数据以及自我隐藏技术,最后讨论了rootkit的检测技术.
关键词: 分层驱动, rootkit, IRP
Abstract: Key windows kernol rootkit based on windows layer drivers have been researched.The techniques of a rootkit attaching itself to the chain of drivers,getting data from IRP and hiding itself are introduced.The techniques of rootkit detection is discussed.
Key words: layer drivers, rootkit, IRP
侯春明, 陈斌. 基于分层驱动的Windows内核rootkit关键技术[J]. journal6, 2009, 30(4): 48-51.
HOU Chun-Ming, CHEN Bin. Key Techniques of Windows Kernol Rootkit Based on Layer Drivers[J]. journal6, 2009, 30(4): 48-51.
导出引用管理器 EndNote|Ris|BibTeX
链接本文: https://zkxb.jsu.edu.cn/CN/
https://zkxb.jsu.edu.cn/CN/Y2009/V30/I4/48