谷歌浏览器插件
订阅小程序
在清言上使用

API monitoring system for defeating worms and exploits in MS-Windows system

INFORMATION SECURITY AND PRIVACY, PROCEEDINGS(2006)

引用 21|浏览0
暂无评分
摘要
Worms and Exploits attacks are currently the most prevalent security problems; they are responsible for over half of the CERT advisories issued in the last three years. To initiate an infection or intrusion, both of them inject a small piece of malicious code (ShellCode) into software through buffer or heap overflow vulnerabilities. Unlike Unix-like operating systems, ShellCodes for Microsoft Windows system need more complex steps to acquire Win32 API calls from DLL file (Dynamic Load Library) in Microsoft Windows. In this paper, we proposed an effective API monitoring system to get rid of worms and exploits attacks for the Microsoft Windows without hardware support. We address the problem by noticing that ShellCodes need the extra complex steps in accessing Win32 API calls. Through the API monitoring system we purposed, we can successfully stop the attacks made by worms and exploits. Moreover, the efficiency of Win32 API Calls hooking and monitoring system can be improved. Incapability to disassemble and analysis the protected software processes are overcome as well.
更多
查看译文
关键词
extra complex step,complex step,microsoft windows,api monitoring system,win32 api call,ms-windows system,unix-like operating system,microsoft windows system,effective api monitoring system,protected software process,win32 api calls,system security,software process,operating system
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要