RESEARCH AND IMPLEMENTATION OF DISK DATA ANALYSIS-BASED STATIC BOOTKIT DETECTION

Ge Jin,Zhi Xue,Yijun Wang
DOI: https://doi.org/10.3969/j.issn.1000-386x.2015.06.013
2015-01-01
Abstract:Bootkit,a novel malicious code,grabs the right of execution by infecting MBR or VBR so that greatly advances the loading time thus disables the effective detection on it by the conventional security software based on dynamic behaviour analysis[1].We propose a novel static detection method in this paper aiming at such a difficulty of Bootkit detection,design and implement correlated MBR matching algo-rithm.Moreover,the experiment is carried out against the Bootkit malicious code sample well-known at home and abroad.Experimental re-sults show that this method can effectively detect today’s mainstream Bootkit malicious codes,and further proves the feasibility of static detec-tion idea.
What problem does this paper attempt to address?