Previous Articles     Next Articles

The Design and Implementation of Suspicious Sample Collection System based on Windows Kernel Driver

ZHANG Tao%JIAO Ying-nan%LU Li-jie%WEN Wei-ping   

  • About author:北京大学软件与微电子学院,北京,102600%国家计算机网络应急技术处理协调中心,北京,100029

Abstract: The study of suspicious sample collection system with the rule-based scanning and procedures behavior analysis based on Windows kernel driver will greatly enhance the comprehensiveness and accuracy of sample collection, and it has important signiifcance to accelerate the discovery of the virus and the virus database updates. Firstly, this paper analyzes the architecture of Windows operating system and then gives the overall system architecture of the suspicious sample collection system based on Windows kernel drivers. Finally, according to the system architecture, the paper detailed designs and implements of each module, and gives examples and the results of a test. The experiment shows that the system is capable of accurately and efifciently collect samples of suspicious information.