02.11.2014 Views

slides

slides

slides

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Hidden Processes<br />

●<br />

●<br />

Common Method To Find Hidden Processes:<br />

●<br />

●<br />

Search for kernel objects hidden in memory<br />

Problem: kernel objects are OS specific; may be<br />

unpredicably altered<br />

Our Alternative Method:<br />

●<br />

●<br />

Bring the search down to the hardware layer and<br />

search for x86 paging structures in memory<br />

Hardware layer is OS independent and much more<br />

difficult to tamper with

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!