The Detection of Hidden Process Technology Based on Thread Scheduling

YAN Guang-lu,LUO Sen-lin
DOI: https://doi.org/10.3969/j.issn.1671-1122.2013.02.010
2013-01-01
Abstract:With the development of Internet,the information technology has become the impetus of economy and society.Windows operating system becomes popular and develops rapidly,so the malicious code for hidden process based on Windows spread quickly.The detection technology for Windows needs to be expanded.This paper will introduce a method to detect hidden processes on 64 bit Windows7 system,which is based on intercept of SwapContext.The experiment shows the method has good reliability and can be used in practical application.
What problem does this paper attempt to address?