Master'sOpen Access

Windows işletim sistemi için ghostware ve rootkit yakalama teknikleri

2006
0 views
0 downloads
Advisor: Yrd. Doç. Dr. Ali Aydın Selçuk

Abstract (EN)

Spyware is a significant problem for most computer users. In public, the termspyware is used with the same meaning as adware, a kind of malicious softwareused for showing advertisements to the user against his will. Spyware programsare also known for their tendency to hide their presence, but advanced stealthtechniques used to be either nonexistent or relatively primitive in terms of effec-tiveness. In other words, most of the spyware programs were efficient at spyingbut not very efficient at hiding. This made spyware easily detectable with sim-ple file-scanning and registry-scanning techniques. New spyware programs havemerged with rootkits and gained stealth abilities, forming spyware with advancedstealth techniques. In this work we focus on this important subclass of spyware,namely ghostware. Ghostware programs hide their resources from the Operat-ing System Application Programming Interfaces that were designed to query andenumerate them. The resources may include files, Windows Registry entries,processes, and loaded modules and files. In this work, we enumerated thesehiding techniques and studied the stealth detection methodologies. We also in-vestigated the effectiveness of the hiding techniques against popular anti-virusprograms and anti-spyware programs together with publicly available ghostwaredetection and rootkit detection tools. The results show that, anti-virus programsor anti-spyware programs are not effective for detecting or removing ghostwareapplications. Hidden object detection or rootkit detection tools can be useful,however, these tools can only work after the computer is infected and they donot provide any means for removing the ghostware. As a result, our work showsthe need for understanding the potential dangers and applications of ghostwareand implementing new detection and prevention tools.Keywords: spyware, ghostware, rootkit, stealth, detection.

Author

Dr. Cumhur Doruk Bozağaç

How to Cite

Cumhur Doruk Bozağaç (Master Thesis). Windows işletim sistemi için ghostware ve rootkit yakalama teknikleri, 2006, Bilkent University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Bilkent University