Windows 7 SP1 for DKOM Under the Attack Technology Research

YIN Liang,WEN Wei-Ping
DOI: https://doi.org/10.3969/j.issn.1671-1122.2011.07.009
2011-01-01
Abstract:Windows records some information in memory,for the purpose of managing objects like process,thread,driver,and reporting the status to user.Because the information is in memory,we can modify it.This paper will show some structs and lists that Windows 7 SP1 created,and introduce some methods to protect and hide processes and drivers.
What problem does this paper attempt to address?