发明名称 Discovery of kernel rootkits by detecting hidden information
摘要 In accordance with a particular embodiment of the present invention, a method of detecting kernel level rootkits includes requesting first information from a kernel level process, the first information including first contents. The first information is received at a user level process. The method also includes compiling second information at kernel level, the second information including second contents corresponding to an expected first contents of the first information. The first contents are compared to the second contents.
申请公布号 US2007079178(A1) 申请公布日期 2007.04.05
申请号 US20050244673 申请日期 2005.10.05
申请人 COMPUTER ASSOCIATES THINK, INC. 发明人 GASSOWAY PAUL A.
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址