作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (14): 13-16. doi: 10.3969/j.issn.1000-3428.2012.14.004

• 专栏 • 上一篇    下一篇

基于心跳行为分析的木马快速检测方法

孟 磊,刘胜利,刘 龙,陈嘉勇,孙海涛   

  1. (解放军信息工程大学信息工程学院,郑州 450002)
  • 收稿日期:2011-10-19 出版日期:2012-07-20 发布日期:2012-07-20
  • 作者简介:孟 磊(1987-),男,硕士研究生,主研方向:网络安全;刘胜利,副教授;刘 龙,助教;陈嘉勇,博士研究生;孙海涛,助理工程师
  • 基金资助:

    郑州市科技创新团队基金资助项目(10CXTD150)

Trojan Rapid Detection Method Based on Heartbeat Behavior Analysis

MENG Lei, LIU Sheng-li, LIU Long, CHEN Jia-yong, SUN Hai-tao   

  1. (Institute of Information Engineering, PLA Information Engineering University, Zhengzhou 450002, China)
  • Received:2011-10-19 Online:2012-07-20 Published:2012-07-20

摘要:

基于通信行为分析的木马检测算法的计算复杂度较高。为此,提出一种基于心跳行为分析的木马快速检测方法,通过对木马通信中心跳行为的描述,选取2个会话特征对木马通信流与正常通信流进行分类,基于该方法设计一个木马快速检测系统TRDS。实验结果表明,TRDS能够在百兆线速网络中快速有效地检测出木马通信。

关键词: 木马检测, 会话特征, 通信流分析, 行为分析, 心跳行为, 快速检测

Abstract:

Trojan detection algorithm based on behavior analysis of communication has high computational complexity. Addressing the problem, this paper proposes a Trojan rapid detection based on heartbeat behavior analysis. The method selects two session attributes to describe the difference between Trojan communication flow and normal communication flow on the basis of description of heartbeat behavior in the Trojan communication large numbers of analysis on Trojan samples. And then Trojan Rapid Detection System(TRDS) is built based on the method. Experimental results show that TRDS can detect the Trojan communication in the 100 Mbit/s network rapidly and efficiently.

Key words: Trojan detection, session feature, communication flow analysis, behavior analysis, heartbeat behavior, rapid detection

中图分类号: