节点文献
基于DLL技术的特洛伊木马植入新方案
New Scheme for the Injection of Trojan Horse Based on DLL
【摘要】 研究了如何将Windows环境下的动态链接库(DLL)技术与远程线程插入技术结合起来实现特洛伊木马植入的新方案。在该方案中,提出了特洛伊木马程序DLL模块化,并且创建了独立的特洛伊木马植入应用程序,由该植入程序实现从特洛伊木马程序中分离出来的植入功能。采用该方案实现的木马植入,具有很好的隐蔽性和灵活性。
【Abstract】 A new scheme is studied to realize the injection of Trojan horse by combining the technology of DLL(dynamic linking library) and that of remote thread injection on the Windows platform. The idea of replacing traditional Trojan horse program with Trojan horse DLL and the notion of creating single Trojan horse injection program to realize the special function of Trojan horse injection are proposed. It is rather safe and flexible to inject Trojan horse by adopting this scheme.
【基金】 国家“863”计划基金资助项目(2001AA121042):“安全主动网技术研究”
- 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2004年18期
- 【分类号】TP311
- 【被引频次】48
- 【下载频次】525