• DocumentCode
    566818
  • Title

    Research on the working mechanism of Bootkit

  • Author

    Gao, Hongbo ; Li, Qingbao ; Zhu, Yu ; Wang, Wei ; Zhou, Li

  • Author_Institution
    China Nat. Digital Switching Syst. Eng. & Technol. Res. Center, Zhengzhou, China
  • Volume
    3
  • fYear
    2012
  • fDate
    26-28 June 2012
  • Firstpage
    476
  • Lastpage
    479
  • Abstract
    As all kinds of defendable and detection software protect information system from destroying by malware effectively, malware becomes more and more advanced too. Current malware continues to penetrate into the underlying bottom of computer system. Bootkit is the newest research product. Bootkit has powerful latent property and resists to most detection tools, which is harmful to information security seriously. In order to research how to detect Bootkit, we have to understand its working mechanism. The research history and actuality of Bootkit is introduced firstly. Moreover several important technologies related to Bootkit are described concretely. Further, the booting process of computer system is analyzed particularly. Then the working mechanism of Bootkit is present comprehensively from three categories of Bootkit. At last, we conclude this paper and indicate future work.
  • Keywords
    BIOS; Bootkit; MBR; NTLDR; infromation security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Science and Digital Content Technology (ICIDT), 2012 8th International Conference on
  • Conference_Location
    Jeju Island, Korea (South)
  • Print_ISBN
    978-1-4673-1288-2
  • Type

    conf

  • Filename
    6269319