发明名称 Detecting user-mode rootkits
摘要 A method and system for determining whether resources of a computer system are being hidden is provided. The security system invokes a high-level function of user mode that is intercepted and filtered by the malware to identify resources. The security system also directly invokes a low-level function of kernel mode that is not intercepted and filtered by the malware to identify resources. After invoking the high-level function and the low-level function, the security system compares the identified resources. If the low-level function identified a resource that was not identified by the high-level function, then the security system may consider the resource to be hidden.
申请公布号 US2007022287(A1) 申请公布日期 2007.01.25
申请号 US20050183225 申请日期 2005.07.15
申请人 MICROSOFT CORPORATION 发明人 BECK DOUGLAS R.;WANG YI-MIN
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址