Design and Implementation of Program Behavior Anomaly Detection System Based on System Service Hook

HAO Dong-bai,GUO Lin,HUANG Hao
DOI: https://doi.org/10.3969/j.issn.1000-7024.2007.18.016
2007-01-01
Abstract:This paper started with monitoring system resource of program access. Registry and file and process resource creation are fo- cused on and associated to detect program behavior anomaly at runtime, a program behavior anomaly detection system is designed and implemented based on operating system service Hook some key techniques of Hook are introduced as well as the design structure and im- plementation points of this system. At last,the experimental result validated the feasibility and availability of this system.
What problem does this paper attempt to address?