Anti-rootkit Technology of Kernel Integrity Detection and Restoration

Yongqiang Zhang,Hai Bi
DOI: https://doi.org/10.1109/ncis.2011.62
2011-01-01
Abstract:Aiming at the principles how root kit malicious action by hooking System Service Dispatch Table and utilizing inline function patching, this paper presents a method of integrity detection and restoration based on kernel file, which is proved to ensure correct implementation of the kernel function.
What problem does this paper attempt to address?