A Windows Rootkit Detection Method Based on Cross-View

Desheng Fu, Shu Zhou, Chenglong Cao · 2010

From the auto-start behavior of rootkit, this paper presented a rootkit detection mechanism based on the hidden registry information, and designed a Windows rootkit detection method based on cross-view. This method by comparing from the kernel mode and user mode enumeration of the registry information found the registry hidden items by rootkit, and then detected the rootkit. Finally, a representative example shows this method has good detection.

Read the paper · More papers on PaperTik