发明名称 |
Discovery of kernel rootkits with memory scan |
摘要 |
A system and method are provided for detecting kernel level rootkits including scanning a kernel memory using a kernel level detector. The kernel level detector includes kernel level code executing in kernel space. The kernel memory is compared to at least one rootkit signature file to determine if a rootkit signature corresponding to the rootkit signature file is present in the kernel memory.
|
申请公布号 |
US2007078915(A1) |
申请公布日期 |
2007.04.05 |
申请号 |
US20050244672 |
申请日期 |
2005.10.05 |
申请人 |
COMPUTER ASSOCIATES THINK, INC. |
发明人 |
GASSOWAY PAUL A. |
分类号 |
G06F17/30 |
主分类号 |
G06F17/30 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|