摘要
监控系统要求具有实时性和隐藏性,远程线程注入技术能实现在Windows系统下进程的隐藏。将监控程序编译成动态链接库(DLL)文件,采用远程线程注入技术注入到系统进程运行,能有效地提高监控系统的安全性能。本文介绍了远程线程注入技术的原理,分析了基于远程线程注入的监控系统的关键技术和实现方法,通过设置定时器的方法解决了系统实时性需求,通过给出的远程线程注入技术解决了隐藏性需求。最后分析采用两级监控和应对安全检测技术来提高监控系统的安全性。
The monitor system demands a characteristic of real time and hiding. The process can be hidden by remote - thread injection technique in Windows system. The monitor program is compiled to DLL and injected into system process to run. In this way, the safety of monitor system can be enhanced effectively. The theory of remote - thread injection technique is presented in this paper. The main technique and implementation method of monitor system based on remote- thread injection technique is analyzed, by setting timer to solve the demands of system' s real time, through the remote - thread injection technique to solve the demands of hiding. At last, the two- stage monitor technique and the responding to safety detection technique are discussed to improving the safety of monitor system.
出处
《计算机技术与发展》
2010年第3期207-210,共4页
Computer Technology and Development
基金
国家高技术(863)计划项目(2007AA01Z179)