Welcome, Guest. Please login or register.
December 11, 2009, 03:53:34 AM

Login with username, password and session length

341633 Posts
37758 Topics
85721 Members

Latest Member: mill

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  HIPS (Host Intrusion Prevention Systems)
| | |-+  SSDT Hooking?
« previous next »
Pages: [1] Go Down Print
Author Topic: SSDT Hooking?  (Read 2329 times)
kosegen
Newbie
*
Offline Offline

Posts: 1


« on: November 16, 2008, 09:05:28 AM »

Hi all, i wanna know what can be done using ssdt hooking as security measure or control? i found some listed below(please tell me if any of them wrong), do you know any other?

WHAT CAN BE DONE

   1. File Protection
   2. Registry Protection
   3. Application Start Control
   4. Application Integrity Check
   5. Services Protection
   6. Devices Protection
   7. Removable Media Restriction
Logged
NiGhtMarEs0nWax
Newbie
*
Offline Offline

Posts: 9


« Reply #1 on: December 06, 2008, 03:32:29 PM »

SSDT hooking will intercept all kernel requests, which is everything. unless the kernel itself is modifed or there is another "hidden OS" installed and set to boot silently, both of which require initial kernel requests to run, because any malicious code requires some kind of environment.  the most ulikely method is a direct installation from your computer terminal, which is a personal security issue.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.063 seconds with 16 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com