›› 2010, Vol. 23 ›› Issue (8): 105-.

• Articles • Previous Articles     Next Articles

Cross-views Process Detection Based on the Hardware-assisted Virtual Machine

 LING Chong, WU Zhi-Yong, SUN Le-Chang, LIU Jing-Ju   

  1. (Department of Network Engineering,Electronic Engineering Institute,PLA,Hefei 230037,China)
  • Online:2010-08-15 Published:2011-03-28


The current process hiding and detection technologies are analyzed,and the mechanism of cross-views discrepancy utilized by Strider GhostBuster are studied in detail,and based on Hardware-Assisted Machine a new framework for process detection is proposed,namely HCDP,whose effectiveness and integrality are verified through experiment.

Key words: process detection;cross-views discrepancy;trusted view;hardware-assisted virtual machine

CLC Number: 

  • TP309.5