摘要
本文通过对木马及木马检测技术的研究,提出了基于行为分析的木马检测技术。主要对木马的行为特征进行抽象描述,首先根据一定的规则建立一个行为特征数据库,并结合启发式分析器来进一步分析判断被检测的程序是否是木马,同时做相应的处理。实验表明,与传统的木马检测技术相比,该算法准确率高,实时性强,占用系统资源少。
Through studying techniques of the Trojan and anti-Trojan,this paper presents the Trojan-detection technology based on behavioral analysis.Through the abstract description of the Trojan's behavior,according to certain rules to establish a behavior feature database,and combining the heuristic analyzer to further analysis and judge whether the program is the Trojans,then do the appropriate processing at last.Comparing with the traditional technology of the Trojan horse detection,the experiments show this algorithm has high accuracy rating,and is effective and efficient in real time;what's more,it takes up little system resources.
出处
《网络安全技术与应用》
2010年第8期9-11,共3页
Network Security Technology & Application
基金
国家自然科学基金项目(No60373003)
河南工业大学校基金项目(No2006BS009)资助
关键词
木马
行为特征
系统调用
行为分析
Trojan
behavioral features
system call
behavioral analysis