作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (6): 198-200.

• 人工智能及识别技术 • 上一篇    下一篇

基于文件静态信息的木马检测模型

戴 敏 1,2,黄亚楼1,王维 2   

  1. 1. 南开大学计算机科学与技术系,天津 300071;2. 天津理工大学计算机科学与工程系,天津 300191
  • 出版日期:2006-03-20 发布日期:2006-03-20

Trojan Horse Detection Model Based on File’s Static Attributes

DAI Min1,2, HUANG Yalou1, WANG Wei2   

  1. 1. Dept. of Computer Science & Technology, Nankai University, Tianjin 300071;2. Dept. of Computer Science & Engineering, Tianjin University of Technology, Tianjin 300191
  • Online:2006-03-20 Published:2006-03-20

摘要: 提出了一种基于文件静态信息检测木马文件的新方法,并以PE 文件为分析对象,利用决策树与基于BP 学习算法的分层网络,设计了基于文件静态信息的木马检测模型,实验证明,该模型能有效地判断文件是否为木马文件。

关键词: 木马检测;数据挖掘;决策树;神经网络;PE 文件

Abstract: A new detecting method based on file’s static attributes is proposed, and intelligent information processing techniques are used to analyze those static attributes, such as decision tree, BP network. Further, a detection model is established to estimate whether a PE file is a Trojan horse. Experimental results validate the work.

Key words: Trojan horses detection; Data mining; Decision tree; Neural networks; Portable executable file