Concepts for the Stealth Windows Rootkit ( The Chameleon Project )
暂无分享,去创建一个
Purpose Many people do not realize the real danger from rootkit technology. One reason for this is probably that publicly available rootkits for Windows OS are relatively easy to detect by conventional methods (i.e. memory scanning based). However, we can imagine some techniques of rootkit implementation, which will be undetectable by these methods, even if the rootkit concept will be publicly available... In order to convince people that traditional rootkit detection is insufficient it would be desirable to have a working rootkit implementing such sophisticated technology. Besides it would be fun.
[1] James Butler,et al. Hidden processes: the implication for intrusion detection , 2003, IEEE Systems, Man and Cybernetics SocietyInformation Assurance Workshop, 2003..