节点文献

基于DLL技术的特洛伊木马植入新方案

New Scheme for the Injection of Trojan Horse Based on DLL

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 潘勉薛质李建华李生红

【Author】 PAN Mian1,XUE Zhi1,LI Jianhua1,LI Shenghong2 (1.School of Information Security Engineering, Shanghai Jiaotong University, Shanghai 200030; 2.Department of Electronic Engineering, Shanghai Jiaotong University, Shanghai 200030)

【机构】 上海交通大学信息安全工程学院上海交通大学电子工程系 上海200030上海200030上海200030

【摘要】 研究了如何将Windows环境下的动态链接库(DLL)技术与远程线程插入技术结合起来实现特洛伊木马植入的新方案。在该方案中,提出了特洛伊木马程序DLL模块化,并且创建了独立的特洛伊木马植入应用程序,由该植入程序实现从特洛伊木马程序中分离出来的植入功能。采用该方案实现的木马植入,具有很好的隐蔽性和灵活性。

【Abstract】 A new scheme is studied to realize the injection of Trojan horse by combining the technology of DLL(dynamic linking library) and that of remote thread injection on the Windows platform. The idea of replacing traditional Trojan horse program with Trojan horse DLL and the notion of creating single Trojan horse injection program to realize the special function of Trojan horse injection are proposed. It is rather safe and flexible to inject Trojan horse by adopting this scheme.

【关键词】 特洛伊木马DLL进程线程植入
【Key words】 Trojan horseDLLProcessThreadInjection
【基金】 国家“863”计划基金资助项目(2001AA121042):“安全主动网技术研究”
  • 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2004年18期
  • 【分类号】TP311
  • 【被引频次】48
  • 【下载频次】525
节点文献中: 

本文链接的文献网络图示:

本文的引文网络