| |||||
| |||||
Search Irongeek.com:
Help Irongeek.com pay for bandwidth and research equipment: |
Intrusion detection and prevention systems monitor a point or set of points
such as a network connection. In response, malware authors hide traffic through
these points with encryption, encoding, and obfuscation. This presentation will
demonstrate a different strategy, based not on another point but on the
flexibility to add almost any point dynamically, with a new function call
hooking system, capable of intercepting virtually any set of API functions
system-wide. This is in contrast to existing HIPS’s, which are limited to
functions chosen during design and only monitor certain actions, such as file
and registry edits. It uses dynamic code generation to expand on existing
hooking techniques, overcoming challenges with different function definitions,
architectures, and associated calling conventions. Matt “scriptjunkie” Weeks
15 most recent posts on Irongeek.com:
|
If you would like to republish one of the articles from this site on your
webpage or print journal please contact IronGeek.
Copyright 2020, IronGeek
Louisville / Kentuckiana Information Security Enthusiast