Netinfo Security ›› 2015, Vol. 15 ›› Issue (2): 57-65.doi: 10.3969/j.issn.1671-1122.2015.02.010

Previous Articles     Next Articles

Research and Implementation on Unknown Trojan Detection System Based on Feature Analysis and Behavior Monitoring

HAO Zeng-shuai1, GUO Rong-hua2, WEN Wei-ping1(), MENG Zheng1   

  1. 1. School of Software & Microelectronics, Peking University, Beijing 102600, China
    2.LEETC, Luoyang Henan 471003, China
  • Received:2014-12-12 Online:2015-02-10 Published:2015-07-05

Abstract:

Trojan is a malicious program that exists mainly to steal user’s personal information and file data, and even to control user’s computer remotely, while hides itself as far as possible. In recent years, the hacker’s behavior has become more professional, interest-oriented, and group-organized, and network intrusion and attacking means have experienced daily changes. Nowadays, Trojan detection depends on the ability of anti-virus software in general, anti-virus software executes Trojan killing usually by using characteristic codes comparison and behavior recognition technology. This way needs anti-virus software to intercept the Trojan samples for analysis, extract the Trojan samples, and identify Trojan after upgrading the Trojan special library. So the hysteresis is very strong, which can’t kill the new Trojans and the Trojans without known characteristics. This paper discusses technology against anti-virus, hiding technology and active defense breakthrough technology, puts forward the Trojan detection method based on feature analysis and behavior monitoring, and completes the design and realization of the unknown Trojan detection system. The system covers the shortage that the existing anti-virus software and security measures can only kill and monitor the known Trojans but can’t identify and kill the unknown Trojans.

Key words: Trojan detection, Trojan killing, feature analysis, behavior monitoring

CLC Number: