Design and Implementation of Program Behavior Analysis System at Ring 0 Level

ZHAO Shuang,LIU Lu,TAO Jing,MA Xiao-bo
DOI: https://doi.org/10.3969/j.issn.1000-3428.2011.01.054
2011-01-01
Abstract:This paper proposes an architecture of program behavior analysis at ring 0 level based on virtual machine on Windows platform and a program behavior analysis system named Malbox is implemented,which is able to detect program's process,file,registry and network behavior in a closed virtual environment.Experiments based on various malware samples prove that Malbox is efficient and performs well on detecting the host and network behavior of programs.
What problem does this paper attempt to address?