Netinfo Security ›› 2014, Vol. 14 ›› Issue (11): 52-58.doi: 10.3969/j.issn.1671-1122.2014.11.009

• Orginal Article • Previous Articles     Next Articles

The Design and Research of Rootkit Detection System Based on Windows API

YUAN Yu-heng, HUANG Geng-xing, GONG Zheng()   

  1. School of Computer Science, South China Normal University, Guangzhou Guangdong 510631,China
  • Received:2014-08-28 Online:2014-11-01 Published:2020-05-18

Abstract:

Rootkit is referred to the malicious software that hides the traces of processes, network ports, files, etc. It is now widely used for the hacker intruding and attacking other peoples’ computer systems. Many computer viruses and spywares also use Rootkit to lurk in the operation system and watch for the proper moment for action. How to detect Rootkit efficiently becomes the key problem to counter these kinds of attacks. On the basis of previous works,this paper discusses the underlying principles of Windows, and developes a Rootkit detection system based on the WINDOWS API. With its help, the user can not only discover different kinds of hidden information of the operation system, but also easily find out the virus and Trojan which are running in the computer and clean them up. To a certain extent, this system enriches the research productions on Rootkit detection, and can offer reference for the follow-up studies.

Key words: Rootkit detection, Windows kernel, operating system

CLC Number: