首页    期刊浏览 2026年01月05日 星期一
登录注册

文章基本信息

  • 标题:Exploiting the Rootkit Paradox with Windows Memory Analysis
  • 本地全文:下载
  • 作者:Jesse Kornblum
  • 期刊名称:International Journal of Digital Evidence
  • 印刷版ISSN:1938-0917
  • 出版年度:2006
  • 卷号:5
  • 期号:01
  • 出版社:International Journal of Digital Evidence
  • 摘要:Rootkits are malicious programs that silently subvert an operating system to hide an intruder's activities. Although there are a number of tools designed to detect rootkits, these programs are competing with the rootkit for system resources and allowing the rootkit to actively evade detection. By taking a memory image of the system, a forensic examiner can conduct a more thorough search for rootkits and even without discovering one directly, infer the presence of one. This paper explores how an examiner can create such a memory image and use the inherent properties of rootkits to find them in those memory images.
国家哲学社会科学文献中心版权所有