摘要
为了有效的检测改进型Rootkit,设计了一种基于优先启动的行为分析检测系统。该系统采用了基于权值系数的智能化行为分析技术,并采用优先启动技术弥补了行为分析技术中探针部署容易受到影响的缺陷。另外,系统在执行路径和总线上阻止Rootkit的非常规加载;设计了报表生成模块以与其它检测软件共享检测信息;采用了文件与进程双重保护以避免Rootkit的破坏。系统对改进型Rootkit具有较好的检测效果,对相关检测软件的设计有较高的参考价值。
In order to detect improved Rootkits effectively,a behavior analysis detection system is designed based on priority starting.This system employes intelligent behavior analysis based on weight coefficients,and uses priority starting to compensate for the flimsiness of probe deployment in behavior analysis.This system stops unconventional Rootkit loading on the bus and execution path.A reporting generation module is designed to share monitoring information with other detection software,and a double protection of documents and processes is used to prevent damage by Rootkits.This system can effectively detect improved Rootkits and is of high reference value to designing other detection software.
出处
《信息工程大学学报》
2011年第5期634-640,共7页
Journal of Information Engineering University
基金
河南省重点科技攻关项目(082102210097)
关键词
行为分析系统
探针部署
优先启动
非常规加载
behavior analysis system
probe deployment
priority starting
unconventional loading