摘要
对比传统木马检测技术的原理及特点,根据网络数据流检测木马的需求,提出一种基于网络通信特征分析的木马识别方法。引入通信指纹的概念扩展通信特征的外延,用实验方法归纳木马在连接、控制和文件传输阶段表现出的通信指纹信息,设计并实现一个启发式木马网络通信指纹识别系统。测试结果表明,该系统运行高效、检测结果准确。
This paper discusses the trojan detection technique,and a detail contrast research of related characters is given.In order to provide trojan detection based on network data flow,a trojan identification method based on network communication fingerprint is broutht forward.The concept of communication fingerprint is introduced to expand the extension of the communication features.Through the experimental method the fingerprints information of trojan for each phase such as connection,control and file transfer can be highlighted.On that basis,a heuristic identification system for trojan based on network communication fingerprint is designed and implemented.Test results indicate that the system runs efficient and the results are accurate.
出处
《计算机工程》
CAS
CSCD
北大核心
2011年第17期119-121,139,共4页
Computer Engineering
基金
四川省应用基础研究基金资助项目(07JY029-011)
四川省教育厅基金资助项目(08ZA043)
关键词
木马识别
通信指纹
启发式
深度包检测
数据流
trojan identification
communication fingerprint
heuristic
Deep Packet Inspection(DPI)
data flow