Publication | Closed Access
In memory detection of Windows API call hooking technique
25
Citations
4
References
2015
Year
Unknown Venue
EngineeringEvasion TechniqueSoftware SystemsComputer ArchitectureWindows ApiSoftware AnalysisOpen ApiHardware SecuritySystem SoftwareMemory ManagementApi Call HookingApi CallRuntime VerificationMemory AnalysisComputer EngineeringMobile MalwareComputer ScienceProgram AnalysisSoftware TestingAnti-virus TechniqueMalware ResearchersMalware Analysis
API call hooking is a technique that malware researchers use to mine malware's API calls. These API calls is used to represent malware's behavior, for use in malware analysis, classification or detection of samples. In this paper, analysis of current Windows API call hooking techniques is presented where surprisingly, it was found that detection of each technique can be done trivially in memory. This could lead to malware being able to sense the presence of API call hooking techniques and modifying their behavior during runtime. Suggestions for a better API call hooking technique are presented towards the end of the paper.
| Year | Citations | |
|---|---|---|
Page 1
Page 1