Code Injection, Process Hollowing, and API Hooking
Code Injection, Process Hollowing, and API Hooking
复制标题
代码注入、Process Hollowing 和 API Hooking
DOI:
10.1007/978-1-4842-6193-4_10
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
Anoop Saldanha
中科院分区:
文献类型:
--
作者:
Abhijit Mohanta;Anoop Saldanha
Malware can drop new files on the system, create new registry keys and values, initiate network connections, create new processes, insert new kernel modules, and so forth. Malware can also force/inject/insert itself into and modify existing running processes, including OS processes and the underlying kernel. But most of these techniques used by the malware for this are not the ones discovered or invented by malware attackers but are techniques used by many of the legitimate software, especially antimalware products.