Research on Concealment Technology of Windows Rootkit

杨彦,黄皓
DOI: https://doi.org/10.3969/j.issn.1000-3428.2008.12.053
2008-01-01
Abstract:Rootkit is a program set which malicious software uses to conceal itself and other specific resources and actions.This paper analyzes and researches on the concealment technologies which representative rootkits on Windows platform commonly use,and classifies them into two categories: modifying kernel object data structures and changing execution paths.The technical principles are described and compared in detail.The future development directions are discussed.
What problem does this paper attempt to address?