170
2 Computer Viruses, Malicious Logic, and Spyware
Fig. 2.25 Interception of rootkit functions in kernel mode
Further access to kernel functions is based on the structure called KeServiceDescriptorTable (SDT) located in ntoskrnl.exe. SDT is a table containing the
addresses of entry points of the NT kernel services. Description of interception
methods and functions can be found in Sven Schreiber’s Undocumented Windows
2000 Secrets; the book also contains the interaction diagram which served as a
prototype for the one presented here. In order to intercept functions, it is necessary to
write a driver that will modify the SDT table. Before modification, the driver needs
to save addresses of the intercepted functions and record addresses of their handlers
in the SDT table. This method is somewhat similar to interception of interruptions
in MS-DOS or the method 2 described above.
This method is often called “Native API interception,” and, naturally, it only works
in NT (and, accordingly, in W2K, XP, W2003). It should be noted that Native APIs
are interrupted not only by rootkits: there are multiple useful programs that intercept
function using SDT alteration; an example of such program would be the popular
utility program RegMon by SysInternals or the Process Guard program.
Note that this method is the simplest but not the only one by far. There are a
number of other methods, in particular, creation of a filter driver. Filter drivers can
be used both to solve monitoring tasks (a classic example would be the FileMon by
SysInternals) and to actively interfere into operation of the system. In particular, a
filter driver can be used to mask files and folders on the drive. The operating principle
of such drivers is based on manipulations with I/O request packets (IRP).
2.5.4 Main Methods of Rootkit Detection in the System
Let us consider the main methods of rootkit detection:
Comparison between two system snapshots (for example, of the list of files on the
drive). The first snapshot is taken in the verified system; the second one is taken after
booting from CD or connecting the inspected HDD to a knowingly clean computer.
This method will ensure detection of any rootkit masking its files on a drive.
Comparison of data returned by API functions of different levels and (or) obtained
by low-level methods (e.g., direct disk reading and analysis of register files). This
Précédent

- 191/839

Suivant