An improved kernel Trojan horse architecture model

mingwei zhao,rongan jiang
DOI: https://doi.org/10.1007/978-3-642-28798-5_18
2012-01-01
Abstract:As a new kind of Trojan horse which combines with the kernel Rootkit technologies, kernel Trojan horse has received a great mount of people's attention and been used a lot. However, the sensitive property of kernel Trojan which follows traditional architecture model is fully exposed to the security software, and needs kernel concealment module to complete all the hidden works, thus the concealment module is too large, easily detected by security software. Based on the analysis of Trojan collaborative concealment model, this paper improves the traditional architecture model and introduces a lightweight concealment module of pure kernel Trojan horse architecture model. Furthermore, an example which adopts the improved model is present in this paper. The experimental results verify the feasibility and efficient of the improved model. © 2012 Springer-Verlag.
What problem does this paper attempt to address?