进程保护技术可以保护一个进程不被非法操作关闭来保证进程的正常运行,这种技术在信息安全的主机防护领域具有其不可替代的作用。进程保护技术可以应用于安全系统、杀毒软件自保护等方面,具有重要的研究价值。通过展开讨论API钩子技术和三线程保护技术的方式,来对进程保护常有的技术作出详细的阐述,并且提供了实现的方法。最后提出把这两种技术结合起来使用的新思路,以达到实现进程保护的最大可靠性。
Process-protecting technology can protect a process from shutting down by illegal operation, it plays an irreplaceable role in host protection field of the information security. The process-protecting technology can be used in self-protecting of security systems and antivirus software, and has significant research value. The paper expounds the frequently used technology in process protection area by discussing API- Hook and three-thread-protecting technologies and advances the implementation approaches of them. At last a new idea of combining them together is brought forward in the paper as well, so as to achieve the highest reliability in realising the process protection.