发明授权
- 专利标题: Automated rootkit detector
- 专利标题(中): 自动Rootkit检测器
-
申请号: US11170792申请日: 2005-06-28
-
公开(公告)号: US07571482B2公开(公告)日: 2009-08-04
- 发明人: Alexey A. Polyakov , Gretchen L. Loihle , Mihai Costea , Robert J. Hensing, Jr. , Scott A. Field , Vincent R. Orgovan , Yi-Min Wang , Yun Lin
- 申请人: Alexey A. Polyakov , Gretchen L. Loihle , Mihai Costea , Robert J. Hensing, Jr. , Scott A. Field , Vincent R. Orgovan , Yi-Min Wang , Yun Lin
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Corporation
- 当前专利权人: Microsoft Corporation
- 当前专利权人地址: US WA Redmond
- 代理机构: Workman Nydegger
- 主分类号: G06F12/14
- IPC分类号: G06F12/14 ; G06F11/00
摘要:
Embodiments of a RootKit detector are directed to identifying a RootKit on a computer that is designed to conceal malware. Aspects of the RootKit detector leverage services provided by kernel debugger facilities to automatically obtain data in specified data structures that are maintained by an operating system. Then the data obtained from the kernel debugger facilities is processed with an integrity checker that determines whether the data contains properties sufficient to declare that a RootKit is resident on the computer.
公开/授权文献
- US20060294592A1 Automated rootkit detector 公开/授权日:2006-12-28