Monitoring Windows Kernel's Services

ABSTRACT<br /> The kernel of Windows operating system provides high-level applications with the low-level functionality needed to perform system operations. This functionality referred to as system services. So, Controlling these services gives the ability to monitor and control important acti...

Full description

Bibliographic Details
Main Author: Rawaa Putros Polos
Format: Article
Language:Arabic
Published: College of Education for Pure Sciences 2010-09-01
Series:مجلة التربية والعلم
Subjects:
Online Access:https://edusj.mosuljournals.com/article_58404_275aae5d2ce1e1cdc3976e9d81014b59.pdf
id doaj-9f645eaad3c14396b6fbf0bbc068a340
record_format Article
spelling doaj-9f645eaad3c14396b6fbf0bbc068a3402020-11-25T01:10:19ZaraCollege of Education for Pure Sciencesمجلة التربية والعلم1812-125X2664-25302010-09-0123311612910.33899/edusj.2010.5840458404Monitoring Windows Kernel's ServicesRawaa Putros PolosABSTRACT<br /> The kernel of Windows operating system provides high-level applications with the low-level functionality needed to perform system operations. This functionality referred to as system services. So, Controlling these services gives the ability to monitor and control important activities of the operating system.<br /> This research presents kernel hooking technique that is one of the most efficient and used technique to achieve system services monitoring.<br /> The aim of the research is how the operating system can be programmatically monitored and controlled on a system-wide basis by means of kernel hooking.<br /> This technique was implemented in a device driver by accessing SSDT (System Service Descriptor Table) to gain the ability for manipulating and change number of effective kernel services for monitoring programs execution, deletion operations and processes termination in the system.<br /> The work has been run successfully on Windows XP SP2 and developed using DDK (Driver Development Kit) for device driver implementation and Visual C++ version 6.0 for application implementation.<br /> So, when the application is executed, programs execution, deletion, and processes termination operations have been controlled, and gives user the capability to permit performing these operations or canceling them.https://edusj.mosuljournals.com/article_58404_275aae5d2ce1e1cdc3976e9d81014b59.pdfwindows kernel&#039;s serviceskernel hookingaccessing ssdt (system service descriptor table)ddk (driver development kit)
collection DOAJ
language Arabic
format Article
sources DOAJ
author Rawaa Putros Polos
spellingShingle Rawaa Putros Polos
Monitoring Windows Kernel's Services
مجلة التربية والعلم
windows kernel&#039;s services
kernel hooking
accessing ssdt (system service descriptor table)
ddk (driver development kit)
author_facet Rawaa Putros Polos
author_sort Rawaa Putros Polos
title Monitoring Windows Kernel's Services
title_short Monitoring Windows Kernel's Services
title_full Monitoring Windows Kernel's Services
title_fullStr Monitoring Windows Kernel's Services
title_full_unstemmed Monitoring Windows Kernel's Services
title_sort monitoring windows kernel's services
publisher College of Education for Pure Sciences
series مجلة التربية والعلم
issn 1812-125X
2664-2530
publishDate 2010-09-01
description ABSTRACT<br /> The kernel of Windows operating system provides high-level applications with the low-level functionality needed to perform system operations. This functionality referred to as system services. So, Controlling these services gives the ability to monitor and control important activities of the operating system.<br /> This research presents kernel hooking technique that is one of the most efficient and used technique to achieve system services monitoring.<br /> The aim of the research is how the operating system can be programmatically monitored and controlled on a system-wide basis by means of kernel hooking.<br /> This technique was implemented in a device driver by accessing SSDT (System Service Descriptor Table) to gain the ability for manipulating and change number of effective kernel services for monitoring programs execution, deletion operations and processes termination in the system.<br /> The work has been run successfully on Windows XP SP2 and developed using DDK (Driver Development Kit) for device driver implementation and Visual C++ version 6.0 for application implementation.<br /> So, when the application is executed, programs execution, deletion, and processes termination operations have been controlled, and gives user the capability to permit performing these operations or canceling them.
topic windows kernel&#039;s services
kernel hooking
accessing ssdt (system service descriptor table)
ddk (driver development kit)
url https://edusj.mosuljournals.com/article_58404_275aae5d2ce1e1cdc3976e9d81014b59.pdf
work_keys_str_mv AT rawaaputrospolos monitoringwindowskernelsservices
_version_ 1725175550097489920