Igor.Korkin edited 4. NEW ROOTKITS DETECTION TOOL.tex  over 9 years ago

Commit id: 6c0354155f937f9f46d47a9703091a8a52e9e4bf

deletions | additions      

       

\section{4. NEW \section{NEW  ROOTKITS DETECTION TOOL} This section is focused on the analysis of the existing approaches to hidden objects (processes and drivers) detection. Their drawbacks will be pointed out and author’s detection approaches will be suggested, which uses Dynamic Bit Signature (DBS) for processes and Rating Point Inspection (RPI) for drivers. Finally, we will describe some currently known disadvantages of the approaches and ways to overcome them and for improvements.