Thursday, October 2, 2008

Rootkit attack and defense in windows vista

What is Rootkit? Rootkit is one kind of special malicious software, its function is in installs information and so on document which, advancement and network link in the goal hides own and assigns, Rootkit generally with the wooden horse, the back door and so on other malicious procedure union use. Rootkit through the load special actuation, the revision system essence, then achieves the hideaway information the goal.
Windows Vista oneself to the malicious software's protection is mainly through the driver digital signature, user access control (UAC) and WindowsDefender realizes, first both to Rootkit kind of evil intention software's defense especially important.
user access control (UAC) is Vista defense evil intention software's other method.
In has opened on the UAC Vista system, user's jurisdiction is equal to having limited the manager jurisdiction, if the user program must to places and so on system plate and registry carries on revision, needs the user to carry on the interactive two confirmations. If the user rejection or is the target program is quite special (for instance wooden horse, back door and so on) not to present the UAC prompt, because is rejected visit to the system directory and registry by Vista, besides extremely individual writing system table of contents's, the majority of target program is not unable to install successfully. The Rootkit procedure similarly will be unable in the UAC environment because of the jurisdiction question to install successfully .

How to protection Rootkit in windows Vista?

1, to keep the Vista system to the latest version of the patch.
2, is not credible source software acquisition, installation and use of the system, pay attention to a variety of tips, particularly related to digital signatures tips.
3, the UAC prompt attention to the information in a timely manner to intercept attempts to modify the risk of system operation.
4, the use of anti-virus software and keep virus to the latest version of the database for malicious software to add a layer of protective security.
5, on a regular basis to support the use of Vista's anti-Rootkit tool for scanning systems.

No comments:

Post a Comment