- 1、本文档共44页,可阅读全部内容。
- 2、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
- 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
- 5、该文档为VIP文档,如果想要下载,成为VIP会员后,下载免费。
- 6、成为VIP后,下载本文档将扣除1次下载权益。下载后,不支持退款、换文档。如有疑问请联系我们。
- 7、成为VIP后,您将拥有八大权益,权益包括:VIP文档下载权益、阅读免打扰、文档格式转换、高级专利检索、专属身份标志、高级客服、多端互通、版权登记。
- 8、VIP文档为合作方或网友上传,每下载1次, 网站将根据用户上传文档的质量评分、类型等,对文档贡献者给予高额补贴、流量扶持。如果你也想贡献VIP文档。上传文档
查看更多
Silberman-Butler RAIDE内部设计文档
RAIDE: Rootkit Analysis Identification Elimination Who Are We? Peter Silberman Undergraduate College Student (*yuck*) Independent Security Research Author of FUTo, (soon to be released PAIMEIdiff) Contributor to http://www.openRCE.org (VISIT THE SITE) Jamie Butler Currently Un-Employed…. ? Software attestation Rootkit detection Author of Rootkits: Subverting the Windows Kernel Co-author of Shadow Walker proof-of-concept memory subversion rootkit Pioneer of Direct Kernel Object Manipulation (DKOM) Agenda What is going to be covered? Quick Review: Define Rootkits Hooks Userland Hooks: Import Address Table (IAT) Export Address Table (EAT) Kernel Hooks: KeServiceDescriptorTable Inline Hooks Entry (Index) Overwrite I/O Request Packet (IRP) Interrupt Descriptor Table Model Specific Registers (MSR) Process Hiding: Old School DKOM (FU) New School FUTo Previous Detection Techniques RAIDE Demo What is a Rootkit? Definition might include a set of programs which patch and Trojan existing execution paths within the system Hooks or Modifies existing execution paths of important operating system functions The key point of a rootkit is stealth our definition includes they must make an attempt to hide some action. Rootkits that do not hide themselves are not then using stealth methods and will be visible to administrative or forensic tools (i.e. DeviceTree from OSR) shows all non-hidden drivers. Userland Hooks IAT hooks Hooking code must run in or alter the address space of the target process If you try to patch a shared DLL such as KERNEL32.DLL or NTDLL.DLL, you will get a private copy of the DLL. Three documented ways to gain execution in the target address space CreateRemoteThread Globally hooking Windows messages Using the Registry HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs EAT Hooks User mode DLL’s and Kernel drivers both export functions Export Address Table is a table of pointers to functions within a module that are callable
您可能关注的文档
- 从硬盘安装Linux操作系统手册.doc
- Windows上搭建Android的JAVA开发环境.doc
- 2014-06-12 QQ农场的安装.doc
- 06常用数字信号分析算法应用实验.doc
- 2011高考语文一轮迎考突破:06扩展语句,压缩语段.doc
- Python进阶06 循环对象.doc
- 第七章 超级链接.ppt
- iometer介绍与使用.doc
- pep小学六年级下册Unit 3 Last weekend period 3.ppt
- PEP 4 四年级下Unit 4 story time课件.ppt
- 人教版九年级英语上册学习资料 第02讲 Unit 2(单元知识、考点).pdf
- 人教版九年级英语上册 2025年秋开学考试卷02.docx
- 人教版九年级英语上册学习资料 第04讲 Unit 4(单元知识、考点).docx
- 人教版八年级英语上册学习资料 第07讲 原级和比较级.pdf
- 2025年秋人教版八年级英语上册 Unit 4 Amazing Plants and Animals(学习、上课).pptx
- 人教版八年级英语上册学习资料 第03讲 Unit 3(单元知识、考点).docx
- 人教版七年级英语下册复习 专题03 介词、数词、连词和频度副词.docx
- 人教版八年级英语下册复习 专题01 动词时态(解析版).pdf
- 人教版九年级英语上册 2025年秋开学考试卷02.pdf
- 人教版八年级英语上册学习资料 第01讲 Unit 1(单元知识、考点).pdf
文档评论(0)