Windows işletim sistemi için ghostware ve rootkit yakalama teknikleri
2006
0 views
0 downloads
Advisor: Yrd. Doç. Dr. Ali Aydın Selçuk
Abstract (EN)
Spyware is a signiï¬cant problem for most computer users. In public, the termspyware is used with the same meaning as adware, a kind of malicious softwareused for showing advertisements to the user against his will. Spyware programsare also known for their tendency to hide their presence, but advanced stealthtechniques used to be either nonexistent or relatively primitive in terms of eï¬ec-tiveness. In other words, most of the spyware programs were eï¬cient at spyingbut not very eï¬cient at hiding. This made spyware easily detectable with sim-ple ï¬le-scanning and registry-scanning techniques. New spyware programs havemerged with rootkits and gained stealth abilities, forming spyware with advancedstealth techniques. In this work we focus on this important subclass of spyware,namely ghostware. Ghostware programs hide their resources from the Operat-ing System Application Programming Interfaces that were designed to query andenumerate them. The resources may include ï¬les, Windows Registry entries,processes, and loaded modules and ï¬les. In this work, we enumerated thesehiding techniques and studied the stealth detection methodologies. We also in-vestigated the eï¬ectiveness of the hiding techniques against popular anti-virusprograms and anti-spyware programs together with publicly available ghostwaredetection and rootkit detection tools. The results show that, anti-virus programsor anti-spyware programs are not eï¬ective for detecting or removing ghostwareapplications. Hidden object detection or rootkit detection tools can be useful,however, these tools can only work after the computer is infected and they donot provide any means for removing the ghostware. As a result, our work showsthe need for understanding the potential dangers and applications of ghostwareand implementing new detection and prevention tools.Keywords: spyware, ghostware, rootkit, stealth, detection.
Author
Dr. Cumhur Doruk Bozağaç
How to Cite
Cumhur Doruk Bozağaç (Master Thesis). Windows işletim sistemi için ghostware ve rootkit yakalama teknikleri, 2006, Bilkent University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Bilkent University
- Geç Antik Çağ'da Aşağı Tuna: Histria örneği(2023)
- Petrol fiyatları ve getiri eğrisi(2024)
- Sözle yönlendirme üzerine makaleler(2014)
- İletişim ağları ve sağlık uygulamaları için çok kollu haydut algoritmaları(2022)
- Türk Anayasa Mahkemesinin içtihatları ışığında karşılaştırmalı anayasal mutluluk(2023)
- Doğrusal karbon zincirlerinin yoğunluk fonksiyoneli teorisi ile incelenmesi(2023)
