首页 | 本学科首页   官方微博 | 高级检索  
     

基于多特征匹配的隐藏进程检测方法
引用本文:周天阳,朱俊虎,王清贤.基于多特征匹配的隐藏进程检测方法[J].计算机应用,2011,31(9):2362-2366.
作者姓名:周天阳  朱俊虎  王清贤
作者单位:信息工程大学 信息工程学院,郑州 450002
基金项目:国家863计划项目(2008AA10Z419);河南省基础与前沿技术研究计划项目(082300410150)
摘    要:利用进程对象特征搜索内存能够检测到隐藏进程。但是,借助不断发展的Rootkit,恶意程序可以修改内存地址映射关系绕过虚拟内存扫描,或篡改进程信息使检测特征失效,从而增加了搜索检测的难度。针对此问题,提出一种基于多特征匹配的隐藏进程检测方法:利用页表项循环补丁技术直接扫描物理内存,得到完整可信的内存信息;选取多个进程数据结构字段构建检测特征模板,提高特征自身的可靠性;引入相似度进行匹配防止单特征失效而导致的漏检。实验结果表明,该方法对隐藏进程具有较好的检测效果。

关 键 词:物理内存搜索    隐藏进程    进程特征    多特征匹配
收稿时间:2011-03-09
修稿时间:2011-05-20

Hidden process detection method based on multi-characteristics matching
ZHOU Tian-yang,ZHU Jun-hu,WANG Qing-xian.Hidden process detection method based on multi-characteristics matching[J].journal of Computer Applications,2011,31(9):2362-2366.
Authors:ZHOU Tian-yang  ZHU Jun-hu  WANG Qing-xian
Affiliation:Institute of Information Engineering, Information Engineering University, Zhengzhou Henan 450002,China
Abstract:Based on certain detection characteristics of process, hidden process could be uncovered by memory searching. However, malware, with the help of developing Rootkit, could hardly be detected because its feature has been manipulated or virtual memory scan could be invalid, thus increasing the difficulty of detection. In order to address this issue, a new multi-characteristics matching approach was proposed. It was to obtain the whole physical memory image by Page Table Entry (PTE) patching, to extract the key fields from process data structure and construct a template to improve the reliability of characteristics, and to introduce similarity for preventing the detection leakage. The results show that the new detection is effective in the hidden process searching.
Keywords:physical memory search                                                                                                                          hidden process                                                                                                                          process characteristic                                                                                                                          multi-characteristics matching
本文献已被 CNKI 等数据库收录!
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号