메뉴 건너뛰기




Volumn 4637 LNCS, Issue , 2007, Pages 219-235

A forced sampled execution approach to kernel rootkit identification

Author keywords

Bayes classifier; Dynamic malware analysis; Intrusion prevention; Rootkit detection; X86 ISA emulation

Indexed keywords

CLASSIFICATION (OF INFORMATION); COMPUTER CRIME; COMPUTER OPERATING SYSTEMS; GRAPH THEORY;

EID: 38149096122     PISSN: 03029743     EISSN: 16113349     Source Type: Book Series    
DOI: 10.1007/978-3-540-74320-0_12     Document Type: Conference Paper
Times cited : (59)

References (32)
  • 4
    • 77952405499 scopus 로고    scopus 로고
    • Raising the bar for windows rootkit detection
    • July
    • Butler, J., Sparks, S.: Raising the bar for windows rootkit detection. Phrack 63 (July 2005)
    • (2005) Phrack , vol.63
    • Butler, J.1    Sparks, S.2
  • 6
    • 38149030556 scopus 로고    scopus 로고
    • Cogswell, B., Russinovich, M.: Rootkitrevealer vl.71 (November 2006), http:// www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx
    • Cogswell, B., Russinovich, M.: Rootkitrevealer vl.71 (November 2006), http:// www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx
  • 8
    • 38149040573 scopus 로고    scopus 로고
    • Corporation, S.: Norton antivirus, http://www.symantec.com/home. homeoffice/ products/overview.jsp?pcid-isftp vid-nav2006
    • Corporation, S.: Norton antivirus, http://www.symantec.com/home. homeoffice/ products/overview.jsp?pcid-isftp vid-nav2006
  • 9
    • 38149127830 scopus 로고    scopus 로고
    • Corporation, S.: Internet security threat report (September 2006), http://www.Symantec.com/enterprise/threatreport/index.jsp
    • Corporation, S.: Internet security threat report (September 2006), http://www.Symantec.com/enterprise/threatreport/index.jsp
  • 10
    • 38149110272 scopus 로고    scopus 로고
    • Automated reverse engineering
    • July
    • Flake, H.: Automated reverse engineering. In: Proceedings of Black Hat 2004 (July 2004)
    • (2004) Proceedings of Black Hat
    • Flake, H.1
  • 11
    • 38149114424 scopus 로고    scopus 로고
    • Fuzen: Fu rootkit, http://www.rootkit.com/project.php7id-12
    • Fuzen: Fu rootkit
  • 16
    • 38149032089 scopus 로고    scopus 로고
    • Kruegel, C., Robertson, W., Vigna, G.: Detecting kernel-level rootkits through binary analysis. In: Yew, P.-C., Xue, J. (eds.) ACSAC 2004. LNCS, 3189, Springer, Heidelberg (2004)
    • Kruegel, C., Robertson, W., Vigna, G.: Detecting kernel-level rootkits through binary analysis. In: Yew, P.-C., Xue, J. (eds.) ACSAC 2004. LNCS, vol. 3189, Springer, Heidelberg (2004)
  • 18
    • 38149066427 scopus 로고    scopus 로고
    • out on rootkits
    • Livingston, B.: Icesword author speaks out on rootkits, http://itmanagement. earthweb.com/columns/executive.tech/article.php/351262i
    • Icesword author speaks
    • Livingston, B.1
  • 22
    • 38149060455 scopus 로고    scopus 로고
    • Research, P.: Rootkit cleaner, http://research.pandasoftware.com/blogs/ research/archive/2006/12/14/Rootkit-cleaner.aspx
    • Research, P.: Rootkit cleaner, http://research.pandasoftware.com/blogs/ research/archive/2006/12/14/Rootkit-cleaner.aspx
  • 28
    • 84857573917 scopus 로고    scopus 로고
    • Sophos: Sophos anti-rootkit, http://www.sophos.com/products/free-tools/ 8ophos-anti-rootkit.html
    • Sophos anti-rootkit
    • Sophos1
  • 29
  • 32
    • 38149107015 scopus 로고    scopus 로고
    • Wikipedia: bayes classifier
    • Wikipedia: Naive bayes classifier, http://en.wikipedia.org/wiki/Naive. Bayes.classifier
    • Naive


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.