Number of transitions between user ring 3 and kernel mode ring 0 in function and items it calls 函數(shù)及其調(diào)用的項(xiàng)中在用戶模式( ring 3 )和內(nèi)核模式( ring 0 )之間轉(zhuǎn)換的次數(shù)。
A change in the location of processor event execution between ring 3 user mode and ring 0 kernel - mode 循環(huán)3 (用戶模式)和循環(huán)0 (內(nèi)核模式)之間的處理器事件執(zhí)行位置的更改。
Number of transitions between user ring 3 and kernel mode ring 0 in function , excluding transitions in items it calls 函數(shù)中用戶模式( ring 3 )和內(nèi)核模式( ring 0 )之間的轉(zhuǎn)換次數(shù),不包括其調(diào)用的項(xiàng)中的轉(zhuǎn)換。
After studying the form of pe files and the execution technique of ring 0 codes in operating system synthetically , a scheme to detect viruses of file type under windows platform has been put forward . the implementation and performance are also mentioned here in detail 在綜合研究了pe文件格式和操作系統(tǒng)ring0代碼執(zhí)行技術(shù)的基礎(chǔ)上,作者提出了一種檢測windows平臺下文件型病毒的方案,并給出了具體實(shí)現(xiàn),得到了比較好的測試結(jié)果。