WANG Wen-bing, FAN Nai-mei and LIU Sheng-li. Design of detection system for BIOS Bootkit in Windows[J]. Journal of Light Industry, 2012, 27(6): 86-89. doi: 10.3969/j.issn.2095-476X.2012.06.023
Citation:
WANG Wen-bing, FAN Nai-mei and LIU Sheng-li. Design of detection system for BIOS Bootkit in Windows[J]. Journal of Light Industry, 2012, 27(6): 86-89.
doi:
10.3969/j.issn.2095-476X.2012.06.023
Design of detection system for BIOS Bootkit in Windows
-
College of Software, Zhengzhou University of Light Industry, Zhengzhou 450001, China;
-
College of Information Engineering, People's Liberation Army Information Engineering University, Zhengzhou 450002, China
-
Received Date:
2012-10-19
Available Online:
2012-09-16
-
Abstract
In order to quickly detect and accurately locate a new deeply concealed Trojan Horse Bootkit,the design of exclusive detecting system to BIOS Bootkit-IBBDS was put forward:IBBDS deposited in the bootable disk,to get the system implementation authority as soon as possible,the BIOS Bootkit capture was realized in the system start-up through the detection for IVT,ISA and HOOK INT 13H module.The validity of this detection method was verified with experiment.
-
-
References
-
[1]
王雷,凌翔.Windows Rootkit进程隐藏与检测技术[J].计算机工程,2010,36(5):140.
-
[2]
朱瑜,刘胜利,陈嘉勇,等.针对插入攻击型Bootkit的分析及检测[J].小型微型计算机系统,2012,33(7):1462.
-
[3]
Stuar Mc Clure,Joel Scambray.Hacking Exposed Network Security Secrets and Solutions[M].New York:McGraw-Hill/Osborne,2012:512-576.
-
[4]
王晓箴,刘宝旭,潘林,等.BIOS恶意代码实现及其检测系统设计[J].计算机工程,2010,36(21):17.
-
[5]
陈文钦.BIOS研发技术剖析[M].北京:清华大学出版社,2001:20-23.
-
[6]
郭彬.Windows实时处理中断程序的设计[J].微型机与应用,1998,17(7):10.
-
Proportional views
-
-