发明名称 Method and apparatus for preventing rootkit installation
摘要 Call to driver load functions, including associated driver objects to be loaded, are stalled and evaluated for indications of a rootkit. When a rootkit is indicated, protective action is taken, and optionally a user or system administrator are notified. Calls not indicative of a rootkit are released and allowed to load. In one embodiment, calls to currently loaded drivers and calls related to installation of new hardware, are excluded from the evaluation for indications of a rootkit. In additional embodiments, sensitive structures and calls to sensitive structures of a computer system are also evaluated for indications of a rootkit.
申请公布号 US7607173(B1) 申请公布日期 2009.10.20
申请号 US20050264117 申请日期 2005.10.31
申请人 SYMANTEC CORPORATION 发明人 SZOR PETER;FERRIE PETER;CONOVER MATTHEW
分类号 G06F12/14;G06F11/00 主分类号 G06F12/14
代理机构 代理人
主权项
地址