Detecting the Code Injection by Hooking System
Calls in Windows ...
implemented as a loadable Windows NT kernel module .... situations, we have to hook system calls in kernel mode. Figure 1. Runti ...
http://dspace.lib.fcu.edu.tw/bitstream/2377/3598/1/ce07ics002006000144.pdf
Bibliography
Russinovich, M., and Cogswell, B. Windows NT System-Call Hooking. Dr. Dobb's. Journal, no. 261, January (1997). San Francisco, CA: CMP Media. Source ...
http://undocumented.rawol.com/sbs-w2k-bibliography.pdf
UNDOCUMENTED
WINDOWS 2000 SECRETS
Exploring Windows 2000 system memory. • Hooking and monitoring calls to the Native API. • Calling kernel functions from user-mode applications ...
http://undocumented.rawol.com/sbs-w2k-preface.pdf
A Live
Digital Forensic system for
Windows networks
Listing 1 HOOK macro. For example, if we want to intercept the Windows NT ZwOpenFile system call, we would use the HOOK macro in the following way: ...
http://www.springerlink.com/index/Y2H0290605R11Q5Q.pdf
Extending
.NET security to unmanaged code
describes a method for hooking operating system calls in. Windows NT by replacing the function pointer in the system call table. ...
http://www.springerlink.com/index/24530581n4518248.pdf
API Spying Techniques for Windows 9x,
NT and 2000
by Y Kaplan - Cited by 17
http://cyphunk.files.wordpress.com/2006/02/API Spying Techniques for Windows 9x, NT and 2000.pdf
A Host Intrusion Prevention System for
Windows Operating Systems
[BDP99] Borate, Dabak, Phadke, Undocumented Windows NT, M&T Books, 1999. [CRu97] Cogswell, Russinovich, Windows NT System-Call Hooking, Dr. Dobb's Jour- ...
http://engsci.aau.dk/kurser/ETC/Nap/Papers/Ips/Presentation13/A Host Intruison Prevention System for Windows Operating Systems.pdf
Understanding Virus Behavior under Windows NT
DOS File Viruses Under Windows NT—System Susceptibility During Boot-up ..... Thus, if a memory-resident virus were to hook into the EXECUTE system service, .... Windows applications to call standard DOS system services directly ...
http://www.symantec.com/avcenter/reference/virus.behavior.under.win.nt.pdf
Layout 3
by E Florio - Cited by 6
http://www.symantec.com/avcenter/reference/when.malware.meets.rootkits.pdf
Winckp: a
Transparent Checkpointing and Rollback Recovery Tool for ...
to applications on Windows NT and Winckp is one of them. .... hook that allows a user application to monitor system events such as ... QueueUserAPC() mechanism on NT to replay all system calls at recovery by application threads, ...
http://ieeexplore.ieee.org/iel5/6328/16917/00781053.pdf
Implementation of Program Behavior Anomaly Detection and ...
and implemented in Windows operating system. Hook and some key techniques of Hook are .... not be lead out (have no this table in NT), its place is ...
http://ieeexplore.ieee.org/iel5/4796932/4797200/04797273.pdf?arnumber=4797273
Undocumented Windows NT
during the system call and the mechanism used for hooking Windows NT system services. The chapter concluded with an example that hooked the NtCreateFileQ ...
http://iimedia.ru:8080/BOOKS/System/Prasad Dabak - Undocumented Windows NT/part_II_6.pdf
New reverse engineering technique using API
hooking and sysenter ...
Hooking Windows NT System Services ... sysenter hooking (2/4). The value in eax registor shows system call number. ntdll.dll(ZwCreateFile) ...
http://www.blackhat.com/presentations/bh-jp-08/bh-jp-08-Aiko/bh-jp-08-Aiko-EN.pdf
A Comparison of Buffer Overflow Prevention Implementations and
...
- Related articles
http://www.blackhat.com/presentations/bh-usa-04/bh-us-04-silberman/bh-us-04-silberman-paper.pdf
Building
VTrace, a Tracer for Windows NT and
Windows 2000
by JR Lorch - 2000 - Cited by 1
http://www.eecs.berkeley.edu/Pubs/TechRpts/2000/CSD-00-1093.pdf
Auto-Start
Entry Point (ASEP) Methods
For example, system call hooking can modify the process list returned by the ... files from the Windows NT file system (NTFS). Or it might manipulate the ...
http://www.malwareinfo.org/files/HowVirusLoads.pdf
Peter Szor
by P Ször - 1999 - Cited by 28
http://www.peterszor.com/memscannt.pdf
Extending
.NET Security to Unmanaged Code
by P Klinkoff - Related articles
http://www.cs.ucsb.edu/~chris/research/doc/isc06_dotnetsec.pdf
Extending .NET Security to Unmanaged Code
by P Klinkoff - Related articles
http://www.cs.ucsb.edu/~vigna/publications/2007_klinkoff_kirda_kruegel_vigna_dotnetsec.pdf
Windows
Device Driver
Windows XP, Windows 2000. This course provides a thorough grounding for Windows ... System Calls. System Call Hooking. Request Flow from Ring 3 to Ring 0 ...
http://www.conceptssys.com/SyllabusPdf/wdd.pdf
Advanced Windows 2000 Rootkit Detection (Execution
Path Analysis)
by JK Rutkowski - Cited by 4
http://craigchamberlain.com/library/malware/Advanced Windows 2000 Rootkit Detection - Execution Path Analysis.pdf
A Method for Detecting Windows Rootkits Douglas R.
Wampler Indiana ...
by DR Wampler - Related articles
http://kappa.slug.louisville.edu/~drwamp01/CATA/wampler-graham-cata2008.pdf
Porting the
Arla file system to Windows
NT
by M Ahltorp - Cited by 2
http://people.su.se/~lha/publications/made2000.pdf
Host-Based
Detection of Worms through Peer-to-Peer Cooperation
by DJ Malan - 2005 - Cited by 29
http://www1.cs.columbia.edu/~angelos/worm05/worm34-malan.pdf
Detecting P2P-Controlled Bots on the Host
by A Nummipuro - Cited by 4
http://www.tml.tkk.fi/Publications/C/25/papers/Nummipuro_final.pdf
Gray-Box
Anomaly Detection using System Call Monitoring
by D Gao - 2007 - Cited by 2
http://www.cs.unc.edu/~reiter/theses/gao.pdf
Safe Termination of Orphan Processes on Windows NT
Platforms
as hooking into the Import Address or Export Address .... from the Windows system . Anti-rootkit security programs normally call the ...
http://www.mcafee.com/us/local_content/white_papers/threat_center/wp_safe_termination_win_nt.pdf
Automated
Known Problem Diagnosis with Event Traces
by C Yuan - 2006 - Cited by 51
http://research.microsoft.com/en-us/people/jrwen/eurosys.pdf
Kernel-mode
Payloads on Windows
: 4.2.4 SharedUserData SystemCall Hook ... work on Windows 2000. However, starting with XP SP0, the system call ...
http://www.hick.org/code/skape/papers/win32-kmode-payloads.pdf
A
Live Digital Forensic System for
Windows Network
System Call Interposition technique on Windows NT family OS: many technical challenges .... HOOK( ZwOpenFile , NewZwOpenFile , OldZwOpenFile ); ...
http://foxp.sourceforge.net/doc/Presentazione FOXP - IFIP.pdf
HIDE 'N SEEK REVISITED – FULL STEALTH IS BACK
10 Mar 2005 ... 'Windows NT System-Call Hooking', Dr. Dobb's. Journal, no.261, January 1997. [11] F-Secure virus descriptions: Lecna. Available from: ...
http://www.f-secure.com/weblog/archives/KimmoKasslin_VB2005_proceedings.pdf
Exploiting
Temporal Consistency to Reduce False Positives in Host ...
by DJ Malan - Cited by 1
http://www.cs.harvard.edu/malan/publications/worm30-malan.pdf
Exploiting Concurrency Vulnerabilities in System
Call Wrappers
by RNM Watson - Cited by 14
http://www.watson.org/~robert/2007woot/2007usenixwoot-exploitingconcurrency.pdf
A C O M P A R I S O N O F F I L E S Y S T E M W O R K L O A D S
System-Call Hooking,” Dr. Dobb's Journal, 22(1), pp. 42–46, January 1997. [Russ97b] M. Russinovich and B. Cogswell, “Examining the. Windows NT Filesystem ...
http://www.usenix.org/publications/library/proceedings/usenix2000/general/full_papers/roselli/roselli.pdf
DIGITAL FX!32: Running 32-Bit x86 Applications on Alpha
NT
Alpha Windows NT 4.0 system. The performance of an x86 application running on a high end Alpha .... Any such call enters the agent's hook for CreateProcess. ...
http://www.usenix.org/publications/library/proceedings/usenix-nt97/full_papers/chernoff/chernoff.pdf
TTAnalyze: A
Tool for Analyzing Malware
by U Bayer - Cited by 64
http://www.iseclab.org/papers/ttanalyze.pdf
The
Measured Performance of Computer Operating Systems Personal
by JB Chen - 1996 - Cited by 97
http://www.scs.stanford.edu/~dm/home/papers/chen:p5.pdf
The
Measured Performance of Personal Computer Operating Systems
by JB Chen - 1995 - Cited by 97
http://www.scs.stanford.edu/~dm/home/papers/chen:p5-sosp.pdf
Dialogic System Software and SDK for
Windows NT
Dialogic System Software and SDK for Windows NT DNA Release Reference. 34. DE_DIGITS Call Status Transition event, you should use the digit type define ...
http://www.cs.cornell.edu/courses/cs519/1998fa/project/Doc/Dialogic/dnarelnt.pdf
F-Secure
Corporation
hook.vxd”). – VxD stays loaded until next restart. • Ring3 to Ring0 jump ... SSDT is write protected in Windows XP but that can be circumvented by disabling the ... NT System Call. NTReadFile(). NTdll.dll. NTReadFile(): Function Table ...
http://www.d-dome.net/papers/Chasing_Ghosts-slides.pdf
musings musings
In Windows NT and its descendants, the num- ... Adore-ng, instead of hook- ing system calls, actually hooks into the Virtual File System (VFS) interface to ...
http://sagecertification.org/publications/login/2005-04/openpdfs/musings0504.pdf
Hybrid
Analysis and Control of Malware Binaries
by KA Roundy - Related articles
ftp://ftp.cs.wisc.edu/paradyn/papers/Roundy09Malware.pdf
Analysis of the
Security of Windows NT
by H Hedbom - 1999 - Cited by 6
http://www.arcert.gov.ar/webs/textos/ntsecure.pdf
Ardence/VenturCom RTX
Windows NT and. Ardence/VenturCom RTX. Windows NT Real Time. eXtension ... RTSS sched preempts NT sched. ● RTX provides : – Bounded system call response ..... NT drivers cannot mask RTSS ITs. • A hook is set in the HAL to catch OUT ...
http://www.ief.u-psud.fr/~mounier/Teaching/RealTime_files/RTCours/rtxSnapshot.pdf
Chocolate: A
Reservation-Based Real-Time Java Environment on ...
by DD Niz - 2000 - Cited by 13
http://eprints.kfupm.edu.sa/29688/1/29688.pdf
Address-Space
Randomization for Windows Systems
by L Li - Cited by 3
http://www.seclab.cs.sunysb.edu/seclab/pubs/acsac06.pdf
0
Objective 1 Introduction 2 Requirements 3 Windows
System Services
StraceNT – System Call Tracer for Windows NT. (Written by: Pankaj Garg). 0 Objective. This document discusses various API spying/hooking techniques for ...
http://www.intellectualheaven.com/Articles/StraceNT.pdf
Usenix00
final
by P Gutmann - Cited by 41
http://www.cypherpunks.to/~peter/usenix00.pdf
K-Tracer:
A System for Extracting Kernel Malware
Behavior
system call in Windows, a rootkit that hides files will mod- ify the results of the system call. ..... systems (based on the NT kernel that includes Windows ..... call hooking technique) because it monitors the creation of ...
http://www.isoc.org/isoc/conferences/ndss/09/pdf/12.pdf
The War in the Stack
by G Zhang - Related articles
http://www.infosecwriters.com/text_resources/pdf/Stack_GZhang.pdf
1 2
