首页> 外国专利> SYSTEM FOR PREVENTING MBR ATTACK USING A CONTROL LIST IN A KERNEL LEVEL AND A COMPUTER READABLE RECORDING MEDIUM RECORDING THE SAME, CAPABLE OF COLLECTING MBR CHANGING INFORMATION EVEN IF A SUSPICIOUS PROCESS DOES NOT CHANGE MBR

SYSTEM FOR PREVENTING MBR ATTACK USING A CONTROL LIST IN A KERNEL LEVEL AND A COMPUTER READABLE RECORDING MEDIUM RECORDING THE SAME, CAPABLE OF COLLECTING MBR CHANGING INFORMATION EVEN IF A SUSPICIOUS PROCESS DOES NOT CHANGE MBR

机译:使用内核级别的控制列表防止MBR攻击的系统,以及使用相同级别的计算机可读记录介质进行记录的MBR攻击系统,即使有类似的过程也不会更改MBR,也能够收集MBR更改信息

摘要

PURPOSE: A system for preventing MOR(Master Boot Record) attack using a control list in a kernel level and a computer readable recording medium recording the same are provided to virtually record MBR change information even if a suspicious process does not change MBR, thereby accurately analyze whether all suspicious process including hidden process is malicious or not in advance.;CONSTITUTION: A system call hooking controller(310) hooks a system call which requests the change of MBR(Master Boot Record) in a OS(Operating System). A control list manager(320) stores a control list including a allowance and denial list. A virtually changing unit(350) record a MBR modification information to a virtually changing storage according to MBR modification information of the system call. A malicious process determiner(340) determines a allowance and denial of the hooking system call based on the control list.;COPYRIGHT KIPO 2010
机译:目的:提供一种用于使用内核级别的控制列表来防止MOR(主引导记录)攻击的系统和一种记录该记录的计算机可读记录介质,即使可疑过程没有改变MBR,也可以虚拟记录MBR变化信息,从而准确地记录MBR变化信息。预先分析所有可疑进程,包括隐藏进程是否是恶意的。控制列表管理器(320)存储包括许可和拒绝列表的控制列表。虚拟改变单元(350)根据系统调用的MBR修改信息将MBR修改信息记录到虚拟改变的存储器中。恶意进程确定器(340)根据控制列表确定允许和拒绝挂钩系统调用。; COPYRIGHT KIPO 2010

著录项

相似文献

  • 专利
  • 外文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号