摘要
在对木马结构和各种内核级rootkit技术进行分析的基础上,提出一种模块化的基于驱动的通用木马结构,该结构能够融合各类内核rootkit,具有通用性,并能有效的将运行在用户态的木马主体部分和运行在内核态的驱动程序部分有机联系起来,驱动程序通过和用户态程序相互通信实现隐蔽通信和木马程序自身的隐藏。测试结果表明,该结构能够很好的支持驱动程序对包括进程、文件、注册表、服务等木马相关信息的隐藏。
On the basis of analysis of the trojan functional structure and different kernel-level rootkit technology, a modularized driverbased trojan structure is put forward, which is generic, and it can deal with different kinds of kernel-level rootkit, contact effectively the main part of Trojan, running in the user mode, with the driver, running in the kernel mode, drivers can achieve the covert communications and hide the Trojan itself by the means of communicating with user-mode code mutually. The result of testing shows that this structure can effectively support the drivers on hiding Trojan-related informations including that of process, file, registry, service and so on.
出处
《计算机工程与设计》
CSCD
北大核心
2008年第16期4156-4158,4161,共4页
Computer Engineering and Design