ISCAS OpenIR
一种通用的Shadow SSDT原始地址获取新方式
Alternative TitleA NOVEL AND GENERAL METHOD ON ACQUIRING ORIGINAL ADDRESSES OF SHADOW SSDT
霍亮; 马恒太; 张楠
2014
Source计算机应用与软件
ISSN1000-386X
Volume31Issue:6Pages:66-68,119
English Abstract挂钩恢复是一项重要的安全技术.对Shadow系统服务描述表(SSDT)挂钩检测以及恢复方法进行分析,传统方法中的原始地址获取方式不仅存在Windows操作系统版本兼容性问题,而且代码逻辑复杂.针对该问题,提出一种通用算法,对ShadowSSDT原始地址获取方法进行改进,并设计了基址重定位方法,减少了代码量,有效提高了稳定性和兼容性.
Indexed TypeCSCD
AbstractHook recovery is one of the important security technologies. We analyse the detection of Shadow system service description table (SSDT) hook and its recovery. In traditional way of original addresses acquisition there are the problems of compatibility in regard to Windows operating system versions and of the complex code logic. In light of this issue,we present a general algorithm,which improves the acquisition means of Shadow SSDT original addresses, and design the base address relocating approach, which reduces the amount of code. They efficiently enhance the stability and compatibility.
KeywordShadow Ssdt Win32k.sys Shadow Ssdt钩子 Shadow Ssdt恢复 Shadow Ssdt Win32k.sys Shadow Ssdt Hook Shadow Ssdt Recovery
Department中国科学院软件研究所天基综合信息系统重点实验室 北京100190;中国科学院大学 北京100190 中国科学院软件研究所天基综合信息系统重点实验室 北京100190
Language中文
CSCD IDCSCD:5157222
Content Type期刊论文
URIhttp://ir.iscas.ac.cn/handle/311060/16741
Collection中国科学院软件研究所
Recommended Citation
GB/T 7714
霍亮,马恒太,张楠. 一种通用的Shadow SSDT原始地址获取新方式[J]. 计算机应用与软件,2014,31(6):66-68,119.
APA 霍亮,马恒太,&张楠.(2014).一种通用的Shadow SSDT原始地址获取新方式.计算机应用与软件,31(6),66-68,119.
MLA 霍亮,et al."一种通用的Shadow SSDT原始地址获取新方式".计算机应用与软件 31.6(2014):66-68,119.
Files in This Item:
There are no files associated with this item.
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[霍亮]'s Articles
[马恒太]'s Articles
[张楠]'s Articles
Baidu academic
Similar articles in Baidu academic
[霍亮]'s Articles
[马恒太]'s Articles
[张楠]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[霍亮]'s Articles
[马恒太]'s Articles
[张楠]'s Articles
Terms of Use
No data!
Social Bookmark/Share
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.