Synthetic approach for Windows Rootkit analysis and detection

ZHANG Li
DOI: https://doi.org/10.3969/j.issn.1674-7720.2009.12.004
2009-01-01
Abstract:This paper analyses the methods of Rootkits detections of nowdays,brings a method of kernel modules compared,checks memory sections integration and hidden driver detection.This method can detect most application layer Rootkits and kernel Rootkits.
What problem does this paper attempt to address?