Метод та засіб виявлення прихованих процесів в операційній системі WINDOWS
| dc.contributor.author | Garnaga, V. A. | en |
| dc.date.accessioned | 2025-08-13T10:03:25Z | |
| dc.date.available | 2025-08-13T10:03:25Z | |
| dc.date.issued | 2025 | |
| dc.description.abstract | The paper describes the methodology and tools for detecting hidden processes in an operating system. The proposed software tool provides detection of hidden processes by directly reading data from physical memory, avoiding dependence on standard API calls that can be compromised by rootkits. Based on the analysis of existing methods, their limitations were identified, including the use of only user mode or reliance on standard kernel mechanisms, which does not provide reliable monitoring in case of manipulation. As a result, we developed a software architecture that includes a modular approach, algorithms for in-depth analysis of system structures, and cross-checking data from various sources. The developed approach allows detecting hidden processes even when using modern methods of masking techniques. The conducted testing has confirmed the effectiveness of the proposed tool, demonstrating its superiority over analogues in the face of real threats. | en |
| dc.identifier.citation | Гарнага В. А., Сокол Д. А. Метод та засіб виявлення прихованих процесів в операційній системі WINDOWS // Матеріали Всеукраїнської науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2025)», Вінниця, 15-16 червня 2025 р. Електрон. текст. дані. 2025. URI: https://conferences.vntu.edu.ua/index.php/mn/mn2025/paper/view/22996. | uk |
| dc.identifier.isbn | 978-617-8163-57-0 | |
| dc.identifier.udc | 004.49 | |
| dc.identifier.uri | https://ir.lib.vntu.edu.ua/handle/123456789/48502 | |
| dc.language.iso | uk_UA | uk_UA |
| dc.publisher | Вінницький національний технічний університет | uk |
| dc.relation.ispartof | Матеріали Всеукраїнської науково-практичної інтернет-конференції «Молодь в науці: дослідження, проблеми, перспективи (МН-2025)», Вінниця, 15-16 червня 2025 р. | uk |
| dc.relation.references | NtQuerySystemInformation function (winternl.h) - Win32 apps. Microsoft Learn: Build skills that open doors in your career. URL: https://learn.microsoft.com/en-us/windows/win32/api/winternl/nfwinternl-ntquerysysteminformation ( : 10.12.2024) | en |
| dc.relation.references | The Art Of Hiding In Windows HADESS. URL: https://hadess.io/the-art-of-hiding-in-windows/ ( : 10.12.2024) | en |
| dc.relation.references | Bypassing User-Mode Hooks and Direct Invocation of System Calls for Red Teams - MDSec. URL: https://www.mdsec.co.uk/2020/12/bypassing-user-mode-hooks-and-direct-invocation-of-systemcalls-for-red-teams/?utm_source=chatgpt.com ( : 10.11.2024). : | en |
| dc.relation.uri | https://conferences.vntu.edu.ua/index.php/mn/mn2025/paper/view/22996 | |
| dc.subject | hidden processes | en |
| dc.subject | physical memory analysis | en |
| dc.subject | rootkit | en |
| dc.subject | operating system | en |
| dc.subject | kernel security | en |
| dc.subject | system structures | en |
| dc.title | Метод та засіб виявлення прихованих процесів в операційній системі WINDOWS | uk |
| dc.type | Thesis |
Файли
Контейнер файлів
1 - 1 з 1
Ліцензійна угода
1 - 1 з 1