Code Injection, Process Hollowing, and API Hooking

Code Injection, Process Hollowing, and API Hooking
复制标题

代码注入、Process Hollowing 和 API Hooking

DOI:
10.1007/978-1-4842-6193-4_10
复制
发表时间:
2020
期刊:
Veterinary Nursing Journal
影响因子:
--
通讯作者:
Anoop Saldanha
Anoop Saldanha
中科院分区:
--
文献类型:
--
作者:
Abhijit Mohanta;Anoop Saldanha

文献摘要

被引文献

相似文献

恶意软件可以在系统上放置新文件,创建新的注册表项和值,启动网络连接,创建新进程,插入新的内核模块,等等。恶意软件还可以强制/注入/插入并修改现有的运行进程,包括操作系统进程和底层内核。但是,恶意软件使用的大多数技术并不是恶意软件攻击者发现或发明的技术,而是许多合法软件,特别是反恶意软件产品使用的技术。
Malware can drop new files on the system, create new registry keys and values, initiate network connections, create new processes, insert new kernel modules, and so forth. Malware can also force/inject/insert itself into and modify existing running processes, including OS processes and the underlying kernel. But most of these techniques used by the malware for this are not the ones discovered or invented by malware attackers but are techniques used by many of the legitimate software, especially antimalware products.