Igor.Korkin edited 4.3. New Stealth Processes and Drivers Detection Approach .tex  over 9 years ago

Commit id: d3b2f2bdd3bc8504a1b68ee861f1b0d997263bd0

deletions | additions      

       

\textun{RPI \textbf{RPI  features and its further development:} It is possible to improve the function ‘check_function_prologue’ by adding an intelligent analyzer, which will detect modified function prologue. It is especially useful when malware employs any kind of armoring (e.g. packers, cryptors).