| 
 | |||||
| 
 | |||||
| 
Search Irongeek.com:   
 Help Irongeek.com pay for bandwidth and research equipment: | 
 
 Intrusion detection and prevention systems monitor a point or set of points 
such as a network connection. In response, malware authors hide traffic through 
these points with encryption, encoding, and obfuscation. This presentation will 
demonstrate a different strategy, based not on another point but on the 
flexibility to add almost any point dynamically, with a new function call 
hooking system, capable of intercepting virtually any set of API functions 
system-wide. This is in contrast to existing HIPS’s, which are limited to 
functions chosen during design and only monitor certain actions, such as file 
and registry edits. It uses dynamic code generation to expand on existing 
hooking techniques, overcoming challenges with different function definitions, 
architectures, and associated calling conventions. Matt “scriptjunkie” Weeks 
15 most recent posts on Irongeek.com: 
 | ||||
If you would like to republish one of the articles from this site on your
webpage or print journal please contact IronGeek.
Copyright 2020, IronGeek
Louisville / Kentuckiana Information Security Enthusiast