节点文献

木马病毒分析及其检测方法研究

Analysis of Trojan Horse and Its Detection

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 朱明徐骞刘春明

【Author】 Zhu Ming Xu Qian Liu Chunming(Automation Department ,The University of Science and Technology of China,Hefei230027)

【机构】 中国科学技术大学自动化系中国科学技术大学自动化系 合肥230027合肥230027合肥230027

【摘要】 特洛依木马作为一种新型的计算机网络病毒,它比其它病毒所构成对网络环境中计算机信息资源的危害都要大。文章对木马病毒特点和所采用技术方法进行了归纳研究,详细介绍了木马病毒在植入、加载、隐蔽、反清除、信息采集和网络通信等六方面所采用的技术方法;在此基础上,提出了基于多Agent协作实现未知新木马病毒自动识别新方法。该方法利用驻留在局域网各机器监测Agent和网络监测Agent所收集的证据和初步判断,并由协作Agent对这些证据和初步判断进行融合印证并做出最终结论。初步实验结果表明,该方法可以有效发现冰河木马病毒和广外女生木马病毒。

【Abstract】 Trojan horse ia a new kind computer virus,which makes much damage to computer information resoureces in a local network.This paper makes induction on charcteristics and techniques used in trojan horse virus,and intro-duces these technoques with respect to implanting,auto-loading,stealthy,anti-clearing,information gathering,communica-tion in the trojan horse virus in detail.From there,a new approach based on multi-agent cooperative to realize trojan horse auto-detection is put forward.In this new method,monitor agents in each network computer and network make initial decision based on their evidence,then cooperative agent makes final decision based on the evidence from all monitor agents through data fusion.Initial experiment shows this method is able to detection IceRiver trojan horse and Broadcasting girl trojan hores.

【关键词】 网络安全木马病毒病毒检测
【Key words】 Network securityTrojan horse virusVirus detection
  • 【文献出处】 计算机工程与应用 ,Computer Engineering and Applications , 编辑部邮箱 ,2003年28期
  • 【分类号】TP309.5
  • 【被引频次】94
  • 【下载频次】1808
节点文献中: 

本文链接的文献网络图示:

本文的引文网络