作者: King Steven , Zimmermann Cat S
DOI:
关键词:
摘要: A security agent for a host computing device may be implemented with multiple levels of indirection from an operating system (OS) kernel the in order to facilitate software upgrades agent. An unserviceable kernel-mode component directly interface OS and hook into function (e.g., callback function) first level indirection, while serviceable agent, which is upgradable, indirectly via second indirection. The configured process events, and/or data related thereto, received monitor activity on malware attacks.