Summary of the invention
In order to solve the problems referred to above, the invention provides a kind of remote control class wooden horse sweep-out method and device, pass through go-between
Attack method simulation main control end sends to the wooden horse of controlled terminal destroys instruction, reaches thoroughly to remove the purpose of trojan horse program.
Described technical scheme is as follows:
First aspect, it is provided that a kind of remote control class wooden horse sweep-out method, it is characterised in that described method includes:
Obtain at least one packet in network traffics;
According to default communication feature rule base, at least one packet described is mated, obtain the data of hit
Bag;
To include that the flow lead of the packet of described hit is to remote control class wooden horse counter device;
Described remote control class wooden horse counter device is connected also with the controlled terminal foundation of described remote control class wooden horse by flow re-injection
Send from destroying instruction;
Described remote control class wooden horse performs destruction after receiving the described instruction of destruction certainly.
In conjunction with first aspect, in the embodiment that the first is possible, at the communication feature rule base that described basis is preset
Mating at least one packet described, before obtaining the packet of hit, described method also includes:
In extraction payload, at least one section of bytecode is as principal character;
Extract at least one attribute character in network message;
Combine to be formed by described principal character and described attribute character and identify the remote communication feature controlling class wooden horse.
In conjunction with first aspect, in the embodiment that the second is possible, the communication feature rule base pair that described basis is preset
At least one packet described mates, and the packet obtaining hit includes:
Described packet is recombinated, decompresses and is deciphered, and with the communication in described default communication feature rule base
Feature is mated;
If communication feature is identical with the communication feature in described default communication feature rule base in described packet, then sentence
Fixed described packet is the packet of described hit.
In conjunction with first aspect, in the embodiment that the third is possible, described will include the stream of the packet of described hit
Amount traction includes to remote control class wooden horse counter device:
According to counter strategy, obtain the information of described flow;
Described flow lead is broken through device to remote control class wooden horse by the information according to described flow;Wherein, described flow
Information includes according to any one in remote control class wooden horse kind, remote control class wooden horse version and protocol port that counter strategy obtains
Or multiple combination.
In conjunction with first aspect, in the 4th kind of possible embodiment, described remote control class wooden horse counter device passes through flow
The controlled terminal of re-injection and described remote control class wooden horse is set up and is connected and sends self-marketing and ruin instruction and include:
The remote main control end controlling class wooden horse described in described remote control class wooden horse counter unit simulation;
After receiving the flow of packet including described hit, set up between the controlled terminal of described remote control class wooden horse
Connect;
Send described from destroying instruction to the controlled terminal of described remote control class wooden horse;Wherein, described remote control class wooden horse counter dress
Put include at least one far the main control end of control class wooden horse communication protocol, at least one far controls class wooden horse and verifies the authentication reached the standard grade
Method and the combination including described any one or more in the payload destroying instruction.
Second aspect, it is provided that device removed by a kind of remote control class wooden horse, it is characterised in that described device includes:
Acquisition module, for obtaining at least one packet in network traffics;
Matching module, at least one packet described being mated according to the communication feature rule base preset,
Packet to hit;
Traction module, the flow lead for the packet by including described hit breaks through device to remote control class wooden horse;
Go-between's module, for the described remote control class wooden horse counter device quilt by flow re-injection with described remote control class wooden horse
Control end is set up to connect and send self-marketing and is ruined instruction;
Destroy module, after described remote control class wooden horse receives the described instruction of destruction certainly, perform destruction.
In conjunction with second aspect, in the embodiment that the first is possible, described device also includes that communication feature builds module,
For:
In extraction payload, at least one section of bytecode is as principal character;
Extract at least one attribute character in network message;
Combine to be formed by described principal character and described attribute character and identify the remote communication feature controlling class wooden horse.
In conjunction with second aspect, in the embodiment that the second is possible, described matching module specifically for:
Described packet is recombinated, decompresses and is deciphered, and with the communication in described default communication feature rule base
Feature is mated;
If communication feature is identical with the communication feature in described default communication feature rule base in described packet, then sentence
Fixed described packet is the packet of described hit.
In conjunction with second aspect, in the embodiment that the third is possible, described traction module specifically for:
According to counter strategy, obtain the information of described flow;
Described flow lead is broken through device to remote control class wooden horse by the information according to described flow;Wherein, described flow
Information includes according to any one in remote control class wooden horse kind, remote control class wooden horse version and protocol port that counter strategy obtains
Or multiple combination.
In conjunction with second aspect, in the 4th kind of possible embodiment, described traction module specifically for:
According to counter strategy, obtain the information of described flow;
Described flow lead is broken through device to remote control class wooden horse by the information according to described flow;Wherein, described flow
Information includes according to any one in remote control class wooden horse kind, remote control class wooden horse version and protocol port that counter strategy obtains
Or multiple combination.
Embodiments provide a kind of remote control class wooden horse sweep-out method and device, by building the logical of remote control class wooden horse
Letter feature database, can identify wooden horse packet in flow, and accuracy is high, and recognition efficiency is high;By the flow lead by hit
To breaking through device, can by counter device the parameter changing in network environment is set, reach truly to simulate main control end and arrive
Purpose;By using flow reinjection technique, simulation main control end is set up with controlled terminal and is connected, thus sends pin to the wooden horse of controlled terminal
Ruin instruction, can thoroughly destroy trojan horse program, improve internet security.
Detailed description of the invention
For making the object, technical solutions and advantages of the present invention clearer, attached below in conjunction with in the embodiment of the present invention
Figure, is clearly and completely described the technical scheme in the embodiment of the present invention, it is clear that described embodiment is only this
Invent a part of embodiment rather than whole embodiments.Based on the embodiment in the present invention, those of ordinary skill in the art exist
Do not make the every other embodiment obtained under creative work premise, broadly fall into the scope of protection of the invention.
See Fig. 1, provide a kind of remote control class wooden horse sweep-out method in a preferred embodiment, especially a kind of based on
The remote control class wooden horse sweep-out method of network side flow reinjection technique, wherein, flow reinjection technique can be any-mode, including but
It is not limited to following: policybased routing, MPLS VPN, two layers of transparent transmission and dual link etc..Specifically include following methods:
S101, at least one packet obtained in network traffics.
Specifically, use flow collection equipment DPI that the packet in network traffics is acquired.At a complete net
In network communication, the form of session between main control end and controlled terminal, is used to communicate, including request bag and the respond packet of transmitting-receiving.
The packet that DPI collects can be request bag can also be in response to bag, can be general data bag can also be wooden horse communication
Packet.
The communication feature rule base that S102, structure are preset.
Specifically, at least one section of bytecode is extracted in payload data payload as principal character;
Extract at least one attribute character in network message;
Combine to be formed by principal character and attribute character and identify the remote communication feature controlling class wooden horse.
Wherein, the attribute character of network message includes: the size of packet, agreement, five-tuple limit, request bag/response
Any one or more combination in bag restriction and time interval etc..
Wherein, payload data payload is obtained by the communication protocol analyzing, deciphering remote control class wooden horse.
By the combination of principal character with attribute character being built the communication feature of specific remote control class wooden horse, merge remote control
The data characteristics of class wooden horse and the data characteristics of network message, can uniquely identify remote control class wooden horse and identify the net at wooden horse place
Network environment.Data arrangement in communication feature and location mode are referred to the data arrangement in general packet and the side of depositing
Formula, is not specifically limited at this.In the communication feature rule base built, the compound mode of communication feature can any combine,
For complicated wooden horse communication feature, can come characterized by multiple communication features and identify.
Optionally, S102 can be after S101, it is also possible to before S101, and execution sequence is not specifically limited.
At least one packet is mated by the communication feature rule base that S103, basis are preset, and obtains the data of hit
Bag.
Specifically, packet is recombinated, decompress and deciphers, and with the communication special in default communication feature rule base
Levy and mate;
After packet being recombinated, decompress and deciphering, by the data message obtained and leading in communication feature rule base
Letter feature is mated successively.Optionally, in order to improve the efficiency of coupling, can the attribute character of first matching network message, treat
After determining, mating principal character item by item.
If communication feature is identical with the communication feature in the communication feature rule base preset in packet, then judge packet
Packet for hit.Otherwise, the execution of method ends.
Wherein, the packet of hit is the wooden horse packet comprising communication feature.
S104, will include that the flow lead of packet of hit is to remote control class wooden horse counter device.
Specifically, according to counter strategy, the information of flow is obtained;
Flow lead is broken through device to remote control class wooden horse by the information according to flow;Wherein, the information of flow includes basis
The group of any one or more in remote control class wooden horse kind, remote control class wooden horse version and protocol port that counter strategy obtains
Close.
Wherein, in S103, the flow of hit can identify remote control class wooden horse kind after recombinating, decompressing and decipher, far control
Class wooden horse version and protocol port, formulate counter strategy according to the above-mentioned information obtained, thus by the flow lead of above-mentioned hit
Corresponding ports to wooden horse counter device.
S105, remote control class wooden horse counter device are set up by the controlled terminal of flow re-injection with remote control class wooden horse and are connected and send
From destroying instruction.
Specifically, remote control class wooden horse counter unit simulation far controls the main control end of class wooden horse;
When, after the flow receiving the packet including hit, setting up the connection between the controlled terminal of remote control class wooden horse;
Controlled terminal to remote control class wooden horse sends described from destroying instruction;Wherein, remote control class wooden horse counter device include to
The communication protocol of the main control end of few a kind of remote control class wooden horse, at least one far controls verification method that the checking of class wooden horse reaches the standard grade and includes
The combination of described any one or more in the payload destroying instruction.
Remote control class wooden horse counter device includes hardware device and software environment, can pass through software mould in terms of software environment
Intend multiple known remote control class wooden horse main control end section communication agreement, and pre-set the verification method that multiple login is reached the standard grade
With from destroying the payload of instruction, when, after the flow receiving the hit come by flow lead, remote control class wooden horse being simulated
Main control end, to network parameter real time modifying, actively sets up the connection with controlled terminal.It is connected with controlled terminal foundation in simulation main control end
Process nature be the process initiating man-in-the-middle attack, be different from blocking technology and Apis cerana Fabricius technology to remote control class wooden horse main control end
Adapter, man-in-the-middle attack uses directly to set up with controlled terminal and is connected.After simulation main control end is connected with controlled terminal foundation, far
Default can be sent to controlled terminal by control class wooden horse counter device from destruction instruction.
S106, remote control class wooden horse perform destruction after being received from destruction instruction.
Operate in the remote control class wooden horse of controlled terminal receive transmission after destroying instruction, perform from destroying task, thoroughly
Destroy the trojan horse program run.In Destruction, run on backstage, do not affect the normal display of controlled terminal equipment and run.
A kind of remote control class wooden horse sweep-out method that the embodiment of the present invention provides, by building the remote communication feature controlling class wooden horse
Storehouse, can identify wooden horse packet in flow, and accuracy is high, and recognition efficiency is high;By by the extremely counter of the flow lead of hit
Device, can by counter device the parameter changing in network environment is set, reach truly to simulate main control end to purpose;Logical
Crossing employing flow reinjection technique, simulation main control end is set up with controlled terminal and is connected, thus sends to the wooden horse of controlled terminal and destroy instruction,
Can thoroughly destroy trojan horse program, improve internet security.
With reference to shown in Fig. 2, in another preferred embodiment of the present invention, it is provided that device removed by a kind of remote control class wooden horse,
This device includes:
Acquisition module 201, for obtaining at least one packet in network traffics;Specifically, flow collection is used to set
Standby DPI obtains at least one packet in network traffics.
Matching module 202, for mating at least one packet according to the communication feature rule base preset, obtains
The packet of hit.
Traction module 203, the flow lead for the packet by including hit breaks through device to remote control class wooden horse.
Go-between's module 204, for remote control class wooden horse counter device by flow re-injection and the remote controlled terminal controlling class wooden horse
Set up to connect and send self-marketing and ruin instruction.
Destroy module 205, after remote control class wooden horse is received from destruction instruction, performs destruction.
Wherein, this device also includes that communication feature builds module 206, is used for:
In extraction payload, at least one section of bytecode is as principal character;
Extract at least one attribute character in network message;
Combine to be formed by principal character and attribute character and identify the remote communication feature controlling class wooden horse.
Specifically, matching module 202 specifically for:
Packet is recombinated, decompress and deciphers, and carry out with the communication feature in default communication feature rule base
Coupling;
If communication feature is identical with the communication feature in the communication feature rule base preset in packet, then judge packet
Packet for hit.
Specifically, traction module 203 specifically for:
According to counter strategy, obtain the information of flow;
Flow lead is broken through device to remote control class wooden horse by the information according to flow;Wherein, the information of flow includes basis
The group of any one or more in remote control class wooden horse kind, remote control class wooden horse version and protocol port that counter strategy obtains
Close.
Go-between's module 204 specifically for:
The main control end of remote control class wooden horse counter unit simulation controlled class wooden horse;
When, after the flow receiving the packet including hit, setting up the connection between the controlled terminal of remote control class wooden horse;
Controlled terminal to remote control class wooden horse sends from destroying instruction.
Wherein, remote control class wooden horse counter device includes the communication protocol, at least of at least one remote main control end of control class wooden horse
A kind of remote control class wooden horse verification method of reaching the standard grade of checking and include described in the payload destroying instruction any one or many
The combination planted.
Embodiments providing a kind of remote control class wooden horse and remove device, communication feature builds module 206 by building
The remote communication feature storehouse controlling class wooden horse, can identify wooden horse packet in flow, and accuracy is high, and recognition efficiency is high;Traction mould
Block 203 passes through the flow lead of hit to breaking through device, can be changed in network environment by arranging of device of counter
Parameter, reaches truly to simulate main control end to purpose;Man-in-the-middle attack module 204, by using flow reinjection technique, simulates master control
Hold to set up with controlled terminal and be connected, thus send to the wooden horse of controlled terminal and destroy instruction, destroy module 205 and pick above-mentioned destruction instruction
After can thoroughly destroy trojan horse program, improve internet security.
It should be understood that described embodiment is only illustrated with the division of described each functional module, actual application
In, as desired the distribution of described function can be completed by different functional modules, will the internal structure of device be divided into
Different functional modules, to complete all or part of function described above.It addition, the remote control class wood that described embodiment provides
Horse sweep-out method and device belong to same design, and it implements process detailed in Example, repeats no more here.
The foregoing is only presently preferred embodiments of the present invention, not in order to limit the present invention, all spirit in the present invention and
Within principle, any modification, equivalent substitution and improvement etc. made, should be included within the scope of the present invention.