Analysis and Detection to Inserted Attacking Bootkit

ZHU Yu,LIU Sheng-li,CHEN Jia-yong,GAO Hong-bo
DOI: https://doi.org/10.3969/j.issn.1000-1220.2012.07.014
2012-01-01
Abstract:Some current Bootkit samples are researched.Based on the understanding of their working principle,a common model of inserted attacking Bootkit is established.Furthermore,a Bootkit detection model is set up aimed at the model of inserted attacking Bootkit and a new detection algorithm is proposed.The new algorithm can not only detect existed samples,but also discover unknown Bootkit which is corresponding with the model of inserted attacking Bootkit.The experimental result indicates that the presented algorithm can effectively detect many kinds of Bootkit based on NT kernel which is running in Windows platform.
What problem does this paper attempt to address?