A Linux kernel-based behavior recorder is implemented in this paper,which has adopted kernel function hijacking technique to hijack and modify kernel functions and also utilized loadable kernel module technique to insert modified functions into kernel.
基于Linux,通过使用内核函数劫持技术劫持并修改键盘输入的相关内核函数,同时利用可装载内核模块技术将修改后的内核函数作为可装载模块插入内核,实现了一个内核级的行为记录器。
CopyRight © 2020-2024 优校网[www.youxiaow.com]版权所有 All Rights Reserved. ICP备案号:浙ICP备2024058711号