提出一种基于支持向量机的内核关键数据定位方法,通过向量机建立分类器对物理内存中执行体进程进行识别,建构可信进程视图.实验结果表明,该方法克服了现阶段利用操作系统版本信息的进程重构方法的缺陷,更具有通用性.
A kernel critical data structure location method based on support vector machine is proposed in this paper. We construct classifier by support vector machine model to classify EPROCESS data structure in raw memory and reconstruct trusted process semantic view. Experimental result shows that the method is more universal, as it overcomes the defect that dependence of operation system version information to reconstruct process semantic view.