Hidden Process Detection Based on Structural Relationship Retrieval

Cheng JIA,Yuezhi ZHOU
DOI: https://doi.org/10.3969/j.issn.1000-3428.2017.09.032
2017-01-01
Abstract:This paper researches the existing implementation methods and detection techniques of hidden processes,and proposes a method of getting process information by retrieving memory.The relationship between process structure and handle structure can be used as a memory retrieval flag to retrieve memory.This method avoids the problem of existing memory retrieval methods that the destroyed retrieval flag can lead to failure of detecting hidden process.This paper designs and implements a hidden process detection system by using cross-view matching technology.Experimental results show that the detection system can realize functions to detect and distinguish hidden processes.
What problem does this paper attempt to address?