DocumentCode :
2103189
Title :
A novel approach of detecting Trojan based on network behavior analysis
Author :
Shicong Li ; Xiaochun Yun ; Yongzheng Zhang ; Yi Pang ; Tao Yin
Author_Institution :
Inst. of Comput. Technol., Beijing, China
fYear :
2012
fDate :
9-11 Nov. 2012
Firstpage :
513
Lastpage :
518
Abstract :
Most existing approaches for detecting Trojan are limited for obfuscation and encryption techniques. In this paper, we present a network behavior analysis designed to address the limitations of previously-proposed approaches. Our solution considered not only transport layer characteristics but also network layer characteristics. The approach in this paper exhibits two major advantages: (1) can better represent Trojan network behavior, and (2) performed at very low computational cost. Based on clustering technique, we proposed a detection model that detects Trojan communication with high accuracy. We implement the model on real-world traces. The experiments show that our model is suitable for detecting Trojan communication amongst the vast amount of network traffic, with over 90% accuracy and less than 3.5% false positive rate. We confidently consider that our detection approach is complementary to the existing techniques.
Keywords :
invasive software; pattern clustering; Trojan communication; clustering technique; detection model; network behavior analysis; network layer characteristics; transport layer characteristics; network behavior analysis; network security; trojan detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communication Technology (ICCT), 2012 IEEE 14th International Conference on
Conference_Location :
Chengdu
Print_ISBN :
978-1-4673-2100-6
Type :
conf
DOI :
10.1109/ICCT.2012.6511272
Filename :
6511272
Link To Document :
بازگشت