Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2012, Vol. 38 ›› Issue (2): 153-155. doi: 10.3969/j.issn.1000-3428.2012.02.050

• Networks and Communications • Previous Articles     Next Articles

Trojan Detection System Based on Weighting of Dynamic and Static Characteristics

ZHONG Ming-quan, LI Huan-zhou, TANG Zhang-guo, ZHANG Jian   

  1. (Institute of Network and Communication Technology, Sichuan Normal University, Chengdu 610066, China)
  • Received:2011-07-04 Online:2012-01-20 Published:2012-01-20

基于动静特征加权的木马检测系统

钟明全,李焕洲,唐彰国,张 健   

  1. (四川师范大学网络与通信技术研究所,成都 610066)
  • 作者简介:钟明全(1975-),男,讲师、硕士,主研方向:网络与信息安全,网络监控;李焕洲,副教授、博士;唐彰国,讲师、硕士;张 健,讲师、博士研究生
  • 基金资助:

    四川省教育厅基金资助项目(08ZA043)

Abstract: In allusion to the shortage of high unreported rate of current detection method for Trojan, using dynamic and static characteristics of Trojan, Trojan detection system based on weighting of dynamic and static characteristics is designed and realized. By in-depth research of work mechanism of Trojan, custom characteristic library for Trojan is built. Detection idea for Trojan and work logic of detection system is introduced, pick-up procedure of Trojan characteristic is analyzed, and distribution method of weight for Trojan characteristic is given. Experimental result proves that the Trojan detection system has high accurate rate.

Key words: Trojan characteristic, dynamic detection, static detection, weighting algorithm

摘要: 传统木马检测方法的漏报率较高。为此,结合木马的动态特征与静态特征,设计并实现一个基于动静特征加权的木马检测系统。研究木马工作机制,建立自定义的木马特征库,介绍木马检测思路和系统工作逻辑,分析木马特征的提取过程,并给出权值分配方法。实验结果表明,该系统的检测准确率较高。

关键词: 木马特征, 动态检测, 静态检测, 加权算法

CLC Number: