节点文献
一种基于网络行为分析的木马检测模型
Trojan Detection Model Based on Network Behavior Analysis
【Author】 Liu Jun-rong1, Wang Wen-jin1,2, Liu Bao-xu1 (1. Computing Center, Institute of High Energy Physics, CAS, Beijing 100049; 2. Graduate University of Chinese Academy of Sciences, Beijing 100049)
【机构】 中国科学院高能物理研究所计算中心; 中国科学院研究生院;
【摘要】 在分析现有木马检测技术的基础上,该论文提出一种基于网络行为分析的木马检测模型。首先将木马网络行为进行抽象化描述,然后根据某些特定的规则建立行为特征库,进而利用支持向量机算法判断是否有木马入侵。最终利用该模型进行木马入侵检测实验,实验表明了这种模型可以有效的检测木马。
【Abstract】 Based on the analysis of existing Trojan detection technology, this paper presents a Trojan detection model based on network behavior analysis. First of all, we abstract description of the Trojan network behavior, then according to certain rules to establish the characteristic behavior library, and then use the support vector machine algorithm to determine whether a Trojan invasion. Finally, through the intrusion detection experiments, shows that this model can effectively detect Trojans.
【Key words】 Trojan Detection; Network Behavior Analysis; Nprobe; SVM;
- 【会议录名称】 第十六届全国核电子学与核探测技术学术年会论文集(下册)
- 【会议名称】第十六届全国核电子学与核探测技术学术年会
- 【会议时间】2012-08-15
- 【会议地点】中国四川绵阳
- 【分类号】TP393.08
- 【主办单位】中国电子学会、中国核学会核电子学与核探测技术分会