A native APIs protection mechanism in the kernel mode against malicious code

21Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.
Get full text

Abstract

As new vulnerabilities on Windows systems are reported endlessly, it is more practical to stop polymorphic malicious code from exploiting these vulnerabilities by building an behavior-based monitor, rather than adopting a signature-based detection system or fixing these vulnerabilities. Many behavior-based monitors have been proposed for Windows systems to serve this purpose. Some of them hook high-level system APIs to detect the suspicious behaviors of code. However, they cannot detect malicious code that directly invokes Native APIs. In this paper, we present a novel security scheme that hooks Native APIs in the kernel mode. This method effectively prevents malicious code calling Native APIs directly. It introduces an average eight percent computation overhead into the system. Analyses and a series of experiments are given in the paper to support our claims. © 2011 IEEE.

Cite

CITATION STYLE

APA

Sun, H. M., Wang, H., Wang, K. H., & Chen, C. M. (2011). A native APIs protection mechanism in the kernel mode against malicious code. IEEE Transactions on Computers, 60(6), 813–823. https://doi.org/10.1109/TC.2011.46

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free