Hidden Processes The Implication for Intrusion Detection隐藏进程的含义用于入侵检测.pptVIP

  • 12
  • 0
  • 约1.21万字
  • 约 63页
  • 2017-03-07 发布于上海
  • 举报

Hidden Processes The Implication for Intrusion Detection隐藏进程的含义用于入侵检测.ppt

Hidden Processes The Implication for Intrusion Detection隐藏进程的含义用于入侵检测

VICE – Catch the hookers! (Plus new rootkit techniques) Jamie Butler Greg Hoglund Agenda Introduction to Rootkits Where to Hook VICE detection Direct Kernel Object Manipulation (DKOM) No hooking required! Demonstration of FU rootkit Operating System Design User Land Operating system provides common API for developers to use Kernel32.dll Ntdll.dll Kernel Mode The low level kernel functions that implement the services needed in user land Protected memory containing objects such as those for processes, tokens, ports, etc. Attack Scenario Attacker gains elevated access to computer system Attacker

文档评论(0)

1亿VIP精品文档

相关文档