首页 | 本学科首页   官方微博 | 高级检索  
     

一种基于内核事件的Windows系统游戏反外挂方法
引用本文:傅建明, 杨铮, 罗陈可, 黄坚伟. 一种基于内核事件的Windows系统游戏反外挂方法[J]. 电子与信息学报, 2020, 42(9): 2117-2125. doi: 10.11999/JEIT190695
作者姓名:傅建明  杨铮  罗陈可  黄坚伟
作者单位:武汉大学国家网络安全学院 空天信息安全与可信计算教育部重点实验室 武汉 430072
基金项目:国家自然科学基金(61972297, U1636107)
摘    要:针对目前客户端反外挂方法的诸多局限,该文提出一种基于内核事件的网络游戏反外挂方法,并实现了反外挂系统CheatBlocker。该方法通过监控Windows系统中的内核事件监视和拦截进程间的异常访问及异常模块注入,同时从内核注入反外挂动态加载库(DLL)用以阻断鼠标键盘的模拟。实验结果表明,CheatBlocker可防御进程模块注入外挂和用户输入模拟类外挂,且具有较低的性能开销。而且,CheatBlocker无需修改内核数据或代码,相比于目前的反外挂系统具有更好的通用性与兼容性。

关 键 词:游戏外挂   反外挂   模块注入   内核事件
收稿时间:2019-09-09
修稿时间:2020-06-13

An Anti-cheat Method of Game Based on Windows Kernel Events
Jianming FU, Zheng YANG, Chenke LUO, Jianwei HUANG. An Anti-cheat Method of Game Based on Windows Kernel Events[J]. Journal of Electronics & Information Technology, 2020, 42(9): 2117-2125. doi: 10.11999/JEIT190695
Authors:Jianming FU  Zheng YANG  Chenke LUO  Jianwei HUANG
Affiliation:Key Laboratory of Aerospace Information Security and Trusted Computing of Ministry of Education, School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China
Abstract:In view of many limitations of current client anti plug-in methods, an anti-cheat method based on kernel events is proposed, and the network game anti-cheat system called CheatBlocker is implemented. This method uses the kernel event monitoring provided by Windows to intercept the abnormal access between processes and the injection of abnormal modules. At the same time, the anti-cheat Dynamic Loaded Library (DLL) injected from the kernel can block the simulation of the mouse keyboard. The experimental results show that CheatBlocker can defend against process module injection cheating and user input simulation cheating, and has low performance overhead. Moreover, CheatBlocker does not need to modify the kernel data or code which ensures the integrity of the kernel and is more compatible than the current anti-cheat systems.
Keywords:Game cheating  Anti-cheating  Module injection  Kernel event
点击此处可从《电子与信息学报》浏览原始摘要信息
点击此处可从《电子与信息学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号