曹磊, 蔡皖东. Windows服务隐藏技术研究与实现[J]. 微电子学与计算机, 2011, 28(12): 10-13.
引用本文: 曹磊, 蔡皖东. Windows服务隐藏技术研究与实现[J]. 微电子学与计算机, 2011, 28(12): 10-13.
CAO Lei, CAI Wan-dong. Research and Implementation of Windows Service Concealing Technology[J]. Microelectronics & Computer, 2011, 28(12): 10-13.
Citation: CAO Lei, CAI Wan-dong. Research and Implementation of Windows Service Concealing Technology[J]. Microelectronics & Computer, 2011, 28(12): 10-13.

Windows服务隐藏技术研究与实现

Research and Implementation of Windows Service Concealing Technology

  • 摘要: 恶意程序利用Windows服务可以实现自启动及部分隐藏功能,研究服务隐藏技术能够提高对此类恶意程序的检测能力.研究了Windows服务的启动过程及服务对象的内部数据结构,提出一种结合内存隐藏和注册表隐藏的多点联合隐藏方法,设计并实现了一个基于该方法的服务隐藏程序,在实验条件下测试了此方法的隐藏效果,分析了应对该类型服务隐藏技术的检测策略.实验证明该方法能够在不影响服务功能的前提下,有效隐藏服务,躲避各类检测工具.

     

    Abstract: Malware may use Windows services to achieve auto-starting and partial concealing.In order to improve the detecting ability to such kind of malware,it is necessary to research the services concealing technology.The boot process of Windows services and the inner data structure of service object are researched,and then a multi-point concealing method combining memory hidden and registry hidden is proposed.Design and realize a service concealing program based on the method,test the hidden effect of the method in experimental conditions,analyze the detecting strategy dealing with this kinds of service concealing technology.The experiment proves that this method can hide service effectively with no influence on the service function,and evade kinds of detecting tools.

     

/

返回文章
返回