Windows下BIOS Bootkit检测系统设计
Design of detection system for BIOS Bootkit in Windows
-
摘要: 为了对新型高隐藏性木马BIOS Bootkit实现快速检测、准确定位,提出一种BIOS Bootkit检测方案:IBBDS存放于引导盘,以尽早获取系统的执行权限,通过对IVT模块、ISA模块和HOOK INT 13H模块的检测,在系统的启动过程即实现对BIOS Bootkit的捕获.试验验证了该检测方法的有效性.
-
关键词:
- BIOS Bootkit /
- Windows /
- 安全防护 /
- 高隐藏性木马
Abstract: In order to quickly detect and accurately locate a new deeply concealed Trojan Horse Bootkit,the design of exclusive detecting system to BIOS Bootkit-IBBDS was put forward:IBBDS deposited in the bootable disk,to get the system implementation authority as soon as possible,the BIOS Bootkit capture was realized in the system start-up through the detection for IVT,ISA and HOOK INT 13H module.The validity of this detection method was verified with experiment.-
Key words:
- BIOS Bootkit /
- Windows /
- security protection /
- deeply concealed Trojan Horse
-
-
[1]
王雷,凌翔.Windows Rootkit进程隐藏与检测技术[J].计算机工程,2010,36(5):140.
-
[2]
朱瑜,刘胜利,陈嘉勇,等.针对插入攻击型Bootkit的分析及检测[J].小型微型计算机系统,2012,33(7):1462.
-
[3]
Stuar Mc Clure,Joel Scambray.Hacking Exposed Network Security Secrets and Solutions[M].New York:McGraw-Hill/Osborne,2012:512-576.
-
[4]
王晓箴,刘宝旭,潘林,等.BIOS恶意代码实现及其检测系统设计[J].计算机工程,2010,36(21):17.
-
[5]
陈文钦.BIOS研发技术剖析[M].北京:清华大学出版社,2001:20-23.
-
[6]
郭彬.Windows实时处理中断程序的设计[J].微型机与应用,1998,17(7):10.
-
[1]
计量
- PDF下载量: 15
- 文章访问数: 845
- 引证文献数: 0