您的位置: 专家智库 > >

国家教育部博士点基金(2012014110002)

作品数:1 被引量:2H指数:1
发文基金:中国博士后科学基金国家教育部博士点基金国家自然科学基金更多>>
相关领域:电子电信更多>>

文献类型

  • 1篇中文期刊文章

领域

  • 1篇电子电信

主题

  • 1篇SOFTWA...
  • 1篇TARGET...
  • 1篇TROJAN
  • 1篇MACHIN...
  • 1篇UNKNOW...
  • 1篇ATTACK

传媒

  • 1篇Wuhan ...

年份

  • 1篇2013
1 条 记 录,以下是 1-1
排序方式:
An Unknown Trojan Detection Method Based on Software Network Behavior被引量:2
2013年
Aiming at the difficulty of unknown Trojan detection in the APT flooding situation, an improved detecting method has been proposed. The basic idea of this method originates from advanced persistent threat (APT) attack intents: besides dealing with damaging or destroying facilities, the more essential purpose of APT attacks is to gather confidential data from target hosts by planting Trojans. Inspired by this idea and some in-depth analyses on recently happened APT attacks, five typical communication characteristics are adopted to describe application’s network behavior, with which a fine-grained classifier based on Decision Tree and Na ve Bayes is modeled. Finally, with the training of supervised machine learning approaches, the classification detection method is implemented. Compared with general methods, this method is capable of enhancing the detection and awareness capability of unknown Trojans with less resource consumption.
LIANG YuPENG GuojunZHANG HuanguoWANG Ying
共1页<1>
聚类工具0