鉴于传统的检测方案无法准确地检测复杂多变的网页木马行为,文中提出一种基于行为特征权重分析的检测模型。总结网页木马的典型行为,利用权重分析的方法进行综合评价,最终根据阈值判别待检测脚本文件是否是网页木马。实验表明,该方法可以有效地检测网页木马,提高检测效率。该检测模型是对基于特征码检测技术的补充,在新型网页木马不断涌现的今天,在基于特征码检测技术中,具有一定的应用意义。
For the traditional detection could not exactly detect the complicated and variable web Trojan behaviors, the web Trojan detection model based on weight analysis of behavior characteristics is proposed. This model could, through summarizing typical behaviors of web Trojan and comprehensively assessing suspected web pages by weight analysis, judge whether they are web Trojans according to the threshold value. The experiment results show that this model could detect web Trojans effectively and accurately, and also a significant supplement to intrusion detection based on code characteristics, and thus is of certain application value in the environment of continuous emergence of new web Trojans.