CN103428223A - 一种木马行为识别方法与系统 - Google Patents
一种木马行为识别方法与系统 Download PDFInfo
- Publication number
- CN103428223A CN103428223A CN2013103816680A CN201310381668A CN103428223A CN 103428223 A CN103428223 A CN 103428223A CN 2013103816680 A CN2013103816680 A CN 2013103816680A CN 201310381668 A CN201310381668 A CN 201310381668A CN 103428223 A CN103428223 A CN 103428223A
- Authority
- CN
- China
- Prior art keywords
- wooden horse
- network
- behavior
- network termination
- identified
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000000034 method Methods 0.000 title claims abstract description 18
- ZXQYGBMAQZUVMI-GCMPRSNUSA-N gamma-cyhalothrin Chemical compound CC1(C)[C@@H](\C=C(/Cl)C(F)(F)F)[C@H]1C(=O)O[C@H](C#N)C1=CC=CC(OC=2C=CC=CC=2)=C1 ZXQYGBMAQZUVMI-GCMPRSNUSA-N 0.000 title abstract 10
- 230000003542 behavioural effect Effects 0.000 claims description 33
- 239000006185 dispersion Substances 0.000 claims description 15
- 230000004044 response Effects 0.000 claims description 14
- 230000005540 biological transmission Effects 0.000 claims description 6
- 238000010586 diagram Methods 0.000 description 3
- 230000006855 networking Effects 0.000 description 2
- 241000700605 Viruses Species 0.000 description 1
- 230000002155 anti-virotic effect Effects 0.000 description 1
- 238000012550 audit Methods 0.000 description 1
- 230000006854 communication Effects 0.000 description 1
- 238000001514 detection method Methods 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 238000010304 firing Methods 0.000 description 1
- 230000006870 function Effects 0.000 description 1
- 238000002513 implantation Methods 0.000 description 1
- 244000144985 peep Species 0.000 description 1
- 230000003068 static effect Effects 0.000 description 1
Images
Landscapes
- Data Exchanges In Wide-Area Networks (AREA)
- Small-Scale Networks (AREA)
Abstract
Description
Claims (10)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310381668.0A CN103428223B (zh) | 2013-08-28 | 2013-08-28 | 一种木马行为识别方法与系统 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310381668.0A CN103428223B (zh) | 2013-08-28 | 2013-08-28 | 一种木马行为识别方法与系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN103428223A true CN103428223A (zh) | 2013-12-04 |
CN103428223B CN103428223B (zh) | 2016-08-10 |
Family
ID=49652399
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201310381668.0A Active CN103428223B (zh) | 2013-08-28 | 2013-08-28 | 一种木马行为识别方法与系统 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN103428223B (zh) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111046600A (zh) * | 2018-10-11 | 2020-04-21 | 株洲中车时代电气股份有限公司 | 一种动态载荷识别方法 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1801030A (zh) * | 2004-12-31 | 2006-07-12 | 福建东方微点信息安全有限责任公司 | 一种区分有害程序行为的方法 |
CN1818823A (zh) * | 2005-02-07 | 2006-08-16 | 福建东方微点信息安全有限责任公司 | 基于程序行为分析的计算机防护方法 |
CN102202064A (zh) * | 2011-06-13 | 2011-09-28 | 刘胜利 | 基于网络数据流分析的木马通信行为特征提取方法 |
CN102571796A (zh) * | 2012-01-13 | 2012-07-11 | 电子科技大学 | 一种移动互联网中僵尸木马防护方法及其系统 |
-
2013
- 2013-08-28 CN CN201310381668.0A patent/CN103428223B/zh active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1801030A (zh) * | 2004-12-31 | 2006-07-12 | 福建东方微点信息安全有限责任公司 | 一种区分有害程序行为的方法 |
CN1818823A (zh) * | 2005-02-07 | 2006-08-16 | 福建东方微点信息安全有限责任公司 | 基于程序行为分析的计算机防护方法 |
CN102202064A (zh) * | 2011-06-13 | 2011-09-28 | 刘胜利 | 基于网络数据流分析的木马通信行为特征提取方法 |
CN102571796A (zh) * | 2012-01-13 | 2012-07-11 | 电子科技大学 | 一种移动互联网中僵尸木马防护方法及其系统 |
Non-Patent Citations (1)
Title |
---|
孙海涛: "基于通信行为分析的木马检测技术研究", 《中国优秀硕士学位论文全文数据库信息科技辑》 * |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111046600A (zh) * | 2018-10-11 | 2020-04-21 | 株洲中车时代电气股份有限公司 | 一种动态载荷识别方法 |
Also Published As
Publication number | Publication date |
---|---|
CN103428223B (zh) | 2016-08-10 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US10212224B2 (en) | Device and related method for dynamic traffic mirroring | |
US9954873B2 (en) | Mobile device-based intrusion prevention system | |
US9256636B2 (en) | Device and related method for application identification | |
JP5029701B2 (ja) | 仮想マシン実行プログラム、ユーザ認証プログラムおよび情報処理装置 | |
TWI489314B (zh) | 用於使用影子網路技術以識別、阻斷及/或延遲對一網路之攻擊的系統及方法 | |
US9584393B2 (en) | Device and related method for dynamic traffic mirroring policy | |
US9230213B2 (en) | Device and related method for scoring applications running on a network | |
US20160191568A1 (en) | System and related method for network monitoring and control based on applications | |
US20140282823A1 (en) | Device and related method for establishing network policy based on applications | |
US7376745B2 (en) | Network address generating system, network address generating apparatus and method, program and storage medium | |
WO2012077603A1 (ja) | コンピュータシステム、コントローラ、及びネットワーク監視方法 | |
TWI514184B (zh) | 用於動態地改變網路狀態之系統及方法 | |
CN102438028B (zh) | 一种防止dhcp服务器欺骗的方法、装置及系统 | |
US20090144818A1 (en) | System and method for using variable security tag location in network communications | |
TW201407405A (zh) | 在一動態電腦網路中過濾通信之防火牆 | |
US9398045B2 (en) | Network device and method for avoiding address resolution protocol attack | |
CN101902482B (zh) | 基于IPv6自动配置实现终端安全准入控制的方法和系统 | |
CN112134893B (zh) | 物联网安全防护方法、装置、电子设备及存储介质 | |
CN104113548B (zh) | 一种认证报文处理方法及装置 | |
CN101820396A (zh) | 一种报文安全性验证的方法和设备 | |
EP3499908B1 (en) | A device and method for the determination of applications running on a network | |
CN103166960A (zh) | 接入控制方法及装置 | |
TW201408023A (zh) | 於原有硬體中實施活動目標技術之系統及方法 | |
CN105978859B (zh) | 一种报文处理的方法和装置 | |
US8745691B1 (en) | System, method, and computer program product for preventing communication of data over a network connection |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
CB02 | Change of applicant information |
Address after: 100094 No. 4, building 8, No. 305, West flourishing road, Haidian District, Beijing Applicant after: BEIJING YONGXIN ZHICHENG TECHNOLOGY CO.,LTD. Address before: 102208, room 530, amber world, No. 85, West Street, Changping District, Beijing, Huilongguan Applicant before: BEIJING YONGXIN ZHICHENG TECHNOLOGY Co.,Ltd. |
|
COR | Change of bibliographic data | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
CB03 | Change of inventor or designer information |
Inventor after: Chen Jun Inventor after: Cai Jingjing Inventor after: Zhang Xuefeng Inventor after: Zhang Heng Inventor before: Chen Jun |
|
CB03 | Change of inventor or designer information | ||
TR01 | Transfer of patent right |
Effective date of registration: 20221118 Address after: 100094 103, building 6, yard 9, FengHao East Road, Haidian District, Beijing Patentee after: BEIJING YONGXIN ZHICHENG TECHNOLOGY CO.,LTD. Patentee after: Beijing Wuyi Jiayu Technology Co.,Ltd. Address before: No. 305, Building 4, Yard 8, Dongbei Wangxi Road, Haidian District, Beijing 100094 Patentee before: BEIJING YONGXIN ZHICHENG TECHNOLOGY CO.,LTD. |
|
TR01 | Transfer of patent right | ||
CP01 | Change in the name or title of a patent holder |
Address after: 100094 103, building 6, yard 9, FengHao East Road, Haidian District, Beijing Patentee after: Yongxin Zhicheng Technology Group Co.,Ltd. Patentee after: Beijing Wuyi Jiayu Technology Co.,Ltd. Address before: 100094 103, building 6, yard 9, FengHao East Road, Haidian District, Beijing Patentee before: BEIJING YONGXIN ZHICHENG TECHNOLOGY CO.,LTD. Patentee before: Beijing Wuyi Jiayu Technology Co.,Ltd. |
|
CP01 | Change in the name or title of a patent holder |