摘要
由于木马等窃密型恶意程序对网络安全的危害性日益增加,为了提高网络入侵检测系统对木马的检测效果,研究分析了木马的网络通信形式和特点,结合一种改进的序列联配算法,设计并实现了一个木马网络通信特征自动提取模型。该模型提高了对木马通信特征进行分析的自动化程度和准确性,实例测试表明了该模型的实用性和有效性。
Aimed at the problems that malwares like Trojan horses are performing more and more harmfully to the network security,to improve the efficiency of Trojan horse detection by NIDS,the characteristics and network communication forms of Trojan horses are analyzed.Then combined a sequence alignment algorithm,a model for signatures automatic generation of Trojan horses is designed and implemented.Finally,this model is proved to be practical and effective by the experiments.
出处
《计算机工程与设计》
CSCD
北大核心
2010年第20期4382-4384,4446,共4页
Computer Engineering and Design
基金
国家863高技术研究发展计划基金项目(2008AA01Z420)
关键词
特洛伊木马
网络通信
入侵检测
序列联配
特征提取
Trojan horse network communication sequence alignment intrusion detection signature generation