Блоги пользователей

2009-05-10 09:54:52

Posted by ECk

Category: Общие

Profense SDK

Profense SDK is a professional software kit for fast developing of any kind of security applications for Microsoft Windows. Simple APIs of Profense SDK include powerful functions: multi layer packet filter (transport layer and channel layer), system services monitor (SDT monitor), IDT monitor, GDT monitor, LDT monitor, registry and filesystem access monitor, NT object manager monitor, filesystem filtering interface, executive objects monitor (processes and threads), executable objects monitor (executable images and sections), state-of-art hidden executive objects monitor (SMM based), abnormal activity monitor (SMM based), abnormal activity monitor (VMM based, including VMX & SVM interfaces), executive objects manipulation interface (using for hidden objects in-memory heuristic search), Patch Guard manipulation interface (using for internal purposes), interface for search of non-exported symbols in kernel environment, real-time instruction tracer interface (using for catching suspicious interception of system services), interface for heuristic detection of exploits (any kind of exploits, Trojans and viruses), IRP_MAJOR procedures monitor (using for proactive defense’s purpose), hardware interrupt monitor (IRQ monitor, using for low-level control of system activity), journal and history logger interface (applicable to any kind of monitor),  transport layer network monitor (TDI based filter), low-level network monitor (NDIS based), TcpIp protocol suite (using for avoiding any malicious interception of network traffic), driver – application communication interface (with two simultaneous channel type – Command channel and Data channel, which renders asynchronous interface to communicate with kernel modules), virtual address manipulation interface (search and enumeration of VAD list on per-process basis), finite state machine for behavior-based detection (proactive defense decision module), network firewall interface with flexible rule system (ALLOW/DENY/CONTENT_BLOCK/CONTENT_MODIFY methods on any active network interface).
Use Profense SDK to add proactive security capabilities to applications that will operate on the Internet to ensure that your application is safe from various attacks, and that once identified, an
Intruder can be blocked from accessing the system on any level (including non-network vectors of attack), without incurring high CPU usage.

Мануал Profense SDK: http://www.profense_sdk_user_manual.zip
Вопросы, предложения: support@profense-sdk.com  support@fxsec.com


Board footer

Powered by PunBB
© Copyright 2002–2005 Rickard Andersson

[ Generated in 0.040 seconds, 13 queries executed ]